Description
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Path Traversal (Remote File Write)
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a classic path traversal flaw in the zipJsonLinesData function of the Create Connection Endpoint, allowing an attacker to manipulate the filePath argument and write or read arbitrary files on the hosting system. The impact of this flaw could be serious, potentially compromising the confidentiality and integrity of data stored on the server or enabling further privilege escalation if configuration files or application binaries are involved. The flaw does not directly grant code execution, but the ability to tamper with files is a significant security risk.

Affected Systems

Any installation of dbgate version 7.3.1 or earlier that has not yet applied a fix for the zipJsonLinesData endpoint is vulnerable. The affected component resides in packages/api/src/utility/zipJsonLinesData.js of the Create Connection Endpoint and is triggered via the publicly exposed API.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but public evidence shows that the exploit code has already been released. Remote exploitation is possible because the malicious filePath can be supplied through the API endpoint, which is accessible from outside the host environment. This combination of a public exploit, the ability to affect arbitrary files, and the lack of an immediate vendor response suggests a real risk to systems running affected versions of dbgate.

Generated by OpenCVE AI on September 28, 2026 at 15:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DBGate to the latest available version that addresses the zipJsonLinesData path traversal. If no newer release exists, monitor vendor channels for an update.
  • Restrict access to the Create Connection Endpoint to trusted IP addresses or authenticated users only, using firewall or API gateway controls.
  • If the endpoint is not required for your deployment, disable or remove it from the API to eliminate the attack surface.

Generated by OpenCVE AI on September 28, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
Title dbgate Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData path traversal
First Time appeared Dbgate
Dbgate dbgate
Weaknesses CWE-22
CPEs cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*
Vendors & Products Dbgate
Dbgate dbgate
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T13:21:52.543Z

Reserved: 2026-09-27T17:01:24.359Z

Link: CVE-2026-101068

cve-icon Vulnrichment

Updated: 2026-09-28T13:21:45.912Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:20.530

Modified: 2026-09-28T14:17:13.390

Link: CVE-2026-101068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T15:45:02Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')