Description
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote arbitrary file write
Action: Immediate Patch
AI Analysis

Impact

A path traversal flaw in the dbgate exportModelSql function allows an attacker to supply a crafted outputFile argument that the system will resolve to a location outside the intended export directory. By manipulating this parameter, the attacker can write arbitrary files to the target host, potentially overwriting configuration files or creating benign documents. The vulnerability does not explicitly grant code execution but enables unauthorized modification of the filesystem, which can be used to disrupt services or prepare for subsequent attacks.

Affected Systems

The flaw impacts dbgate versions 7.3.1 and earlier. The affected component is packages/api/src/controllers/databaseConnections.js within the Export Handler. Users running these versions are exposed to the path traversal vulnerability.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. Although the EPSS score is unavailable and the flaw is not listed in the CISA KEV catalog, a publicly available exploit demonstrates that the vulnerability can be targeted remotely via crafted HTTP requests that trigger the path traversal. The risk is therefore significant for installations that expose the Export Handler to untrusted network traffic, as the ability to write files can lead to data integrity issues and facilitate further lateral movement.

Generated by OpenCVE AI on September 28, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade dbgate to a version newer than 7.3.1 or apply any vendor fix that addresses the path traversal flaw.
  • If upgrading is not immediately possible, disable or restrict external access to the Export Handler feature to block use of exportModelSql.
  • Sanitize and validate the outputFile parameter in the application, ensuring it does not contain traversal characters and is confined to a safe, pre‑defined directory; also tighten file system permissions to limit write access for the dbgate process.

Generated by OpenCVE AI on September 28, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title dbgate Export databaseConnections.js exportModelSql path traversal
First Time appeared Dbgate
Dbgate dbgate
Weaknesses CWE-22
CPEs cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*
Vendors & Products Dbgate
Dbgate dbgate
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T14:38:14.052Z

Reserved: 2026-09-27T17:01:30.406Z

Link: CVE-2026-101069

cve-icon Vulnrichment

Updated: 2026-09-28T14:38:10.144Z

cve-icon NVD

Status : Deferred

Published: 2026-09-28T13:17:20.747

Modified: 2026-09-28T15:17:12.440

Link: CVE-2026-101069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')