Sceawere
Vulnerability Detail
CVE-2026-101067UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Path Traversal in dbgate
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- dbgate
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T13:17:20.313Z",
"pubdate": "2026-09-28T13:17:20.313Z",
"executiveSummary": "A path traversal vulnerability exists within the dbgate application, specifically affecting the save-uploaded-file endpoint. This vulnerability, identified in versions up to 6.8.1, 7.0.2, 7.1.8, 7.2.5, and 7.3.1, allows remote attackers to manipulate file paths during the upload process.\nThe vulnerability resides in the saveUploadedFile function within the files.js file. By injecting directory traversal sequences (e.g., ../) into the filePath or fileName arguments, an attacker can bypass intended directory restrictions, leading to arbitrary file write operations on the server filesystem.\nThe risk implication is critical, as successful exploitation enables remote attackers to write or overwrite sensitive files, potentially leading to remote code execution (RCE) or system compromise. The vulnerability is reachable over a network, and public exploits are available, increasing the likelihood of active exploitation. The vendor has not addressed the reported issue, leaving affected installations without an official patch.",
"technicalDetails": "The vulnerability is a path traversal (directory traversal) flaw located in the save-uploaded-file endpoint of the dbgate application. The root cause is the improper validation and sanitization of user-supplied input—specifically the filePath and fileName arguments—before using these values in file system operations within the saveUploadedFile function in files.js.\nThe application fails to neutralize path traversal sequences, such as '../', which allow an attacker to escape the designated upload directory. By crafting a malicious request, an attacker can manipulate the destination path, allowing them to traverse the directory structure outside the intended application scope.\nThe attack flow proceeds as follows: First, the attacker identifies a request to the save-uploaded-file endpoint. Second, the attacker intercepting or crafting a request modulates the filePath or fileName parameter to include malicious traversal sequences (e.g., ../../../etc/passwd or a path to a web application directory like ../app/config.json). Third, the vulnerable saveUploadedFile function processes the input without verifying that the resolved path resides within the authorized storage directory. Fourth, the server executes a file write operation using the attacker-controlled path, resulting in the creation or modification of files at an arbitrary location accessible by the user running the dbgate service.\nThis vulnerability is remotely exploitable and does not explicitly require authenticated access based on the nature of the endpoint. The impact of this exploit is severe, as it grants an attacker the ability to overwrite critical system configuration files, inject malicious code into application source files to achieve code execution, or corrupt database files managed by dbgate. Because public exploit scripts are available, the barrier to entry for exploitation is low, significantly increasing the risk to environments where dbgate is exposed to the network.\nThe lack of vendor response means that the inherent logical flaw in file handling remains unmitigated in the listed versions, requiring immediate administrative intervention to prevent exploitation."
}