Impact
A path‑traversal flaw exists in the Files Endpoint of dbgate, specifically through the runid parameter in runners.js. The flaw permits an attacker to manipulate the runid argument to reference files outside the intended directory, potentially allowing the reading of arbitrary files located on the host system. This vulnerability can be triggered remotely by sending crafted requests and has been publicly disclosed.
Affected Systems
Versions of dbgate up to and including 7.3.1 are affected. The reported issue resides in the component Files Endpoint, in the file packages/api/src/controllers/runners.js, and applies to all built‑in releases of the open‑source product, without a vendor‑supplied fix currently available.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and no EPSS score is available; the vulnerability is not listed in the CISA KEV catalog. Because the path traversal can be exercised remotely and the public exploit is available, exposed installations remain at risk of confidential data exposure. The absence of an immediate patch extends the window during which attackers can exploit the flaw.
OpenCVE Enrichment