Sceawere
Vulnerability Detail
CVE-2026-101066UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DbGate Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- dbgate
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T13:17:20.080Z",
"pubdate": "2026-09-28T13:17:20.080Z",
"executiveSummary": "A path traversal vulnerability has been identified in the Archive Link Creation component of DbGate, specifically affecting versions up to 7.3.1.\nThe vulnerability resides within the createLink function located in packages/api/src/controllers/archive.js.\nBy manipulating the 'linkedFolder' argument, a remote, unauthenticated attacker can escape the intended directory boundaries, leading to unauthorized access to the underlying file system.\nThis flaw allows for the arbitrary reading or manipulation of files outside the designated web root or archive directory, posing a significant risk to data confidentiality and system integrity.\nAs the exploit has been publicly disclosed and the vendor has remained unresponsive, the risk to deployments is elevated, necessitating immediate defensive measures to restrict file access.",
"technicalDetails": "The vulnerability is caused by improper neutralization of special elements used in file path sequences within the 'linkedFolder' argument provided to the createLink function. The function fails to sanitize or validate the user-supplied input before using it in file system operations.\nIn the affected file packages/api/src/controllers/archive.js, the application logic constructs a file path based on the input string provided by the user. An attacker can leverage directory traversal sequences, such as '../', to bypass intended folder restrictions.\nThe attack flow initiates with a remote request sent to the DbGate API endpoint responsible for archive link creation. The attacker supplies a crafted 'linkedFolder' payload containing traversal sequences designed to navigate outside the application's root directory.\nBecause the application lacks adequate path normalization or canonicalization checks, the backend system processes the malicious path as a legitimate file system operation. This permits the attacker to interact with sensitive files or directories stored on the host server that the application process has permission to access.\nThe vulnerability is exploitable remotely, requiring no specific authentication or elevated privileges, depending on the exposure of the API endpoint. Successful exploitation enables unauthorized read access to configuration files, system credentials, or other sensitive data residing on the server, potentially leading to full system compromise depending on the user context under which the DbGate process is executing.\nThe lack of vendor response indicates that no official patch is currently available for versions up to 7.3.1, leaving installations relying on default configurations at continued risk of exploitation via public PoC code."
}