Description
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Remote Path Traversal allowing arbitrary file read
Action: Assess Impact
AI Analysis

Impact

A path‑traversal flaw exists in the Files Endpoint of dbgate, specifically through the runid parameter in runners.js. The flaw permits an attacker to manipulate the runid argument to reference files outside the intended directory, potentially allowing the reading of arbitrary files located on the host system. This vulnerability can be triggered remotely by sending crafted requests and has been publicly disclosed.

Affected Systems

Versions of dbgate up to and including 7.3.1 are affected. The reported issue resides in the component Files Endpoint, in the file packages/api/src/controllers/runners.js, and applies to all built‑in releases of the open‑source product, without a vendor‑supplied fix currently available.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and no EPSS score is available; the vulnerability is not listed in the CISA KEV catalog. Because the path traversal can be exercised remotely and the public exploit is available, exposed installations remain at risk of confidential data exposure. The absence of an immediate patch extends the window during which attackers can exploit the flaw.

Generated by OpenCVE AI on September 28, 2026 at 16:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any official patch or update from dbgate; if none is released, proceed with mitigations.
  • Restrict network access to the dbgate API by placing a firewall or reverse‑proxy in front, allowing only trusted IP ranges.
  • Run dbgate under a non‑privileged user and enforce file‑system permissions that limit read access to the application directory and deny access to sensitive directories.
  • Implement input validation on the runid parameter to reject path traversal sequences such as ".." or absolute paths.

Generated by OpenCVE AI on September 28, 2026 at 16:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title dbgate Files Endpoint runners.js files path traversal
First Time appeared Dbgate
Dbgate dbgate
Weaknesses CWE-22
CPEs cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:*
Vendors & Products Dbgate
Dbgate dbgate
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T13:15:09.738Z

Reserved: 2026-09-27T17:01:35.923Z

Link: CVE-2026-101070

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:13.543

Modified: 2026-09-28T14:17:13.717

Link: CVE-2026-101070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')