Impact
DbGate is a cross‑platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution. An attacker with valid credentials can supply an unsanitized functionName parameter to the /runners/load‑reader endpoint, allowing arbitrary OS commands to be executed as root. The require = null mitigation can be bypassed through dynamic import, leaving the flaw fully exploitable. The vulnerability is addressed in version 7.1.9.
Affected Systems
The affected product is dbgate:dbgate. All releases up to and including version 7.1.8 are vulnerable; the issue was fixed in version 7.1.9. Users must ensure they are running a patched release.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. With an EPSS score of 2 %, the probability of exploitation is low but not negligible. The vulnerability is not listed in CISA’s KEV catalog, meaning no known large‑scale exploitation has been reported. Attackers would need network access to the DbGate service and valid credentials, after which they can launch arbitrary commands. The impact is complete control over the host running DbGate, including privileged execution.
OpenCVE Enrichment
Github GHSA