Sceawere
Vulnerability Detail
CVE-2026-101068UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DbGate Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- dbgate
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-28T13:17:20.530Z",
"pubdate": "2026-09-28T13:17:20.530Z",
"executiveSummary": "A path traversal vulnerability exists in the Create Connection Endpoint component of DbGate, specifically affecting versions up to 7.3.1. The flaw resides in the zipJsonLinesData function within packages/api/src/utility/zipJsonLinesData.js. This vulnerability allows an unauthenticated or remote attacker to manipulate the filePath argument, potentially leading to unauthorized file system access. The vulnerability poses a significant risk as it allows for arbitrary file operations, which could lead to sensitive data exposure or further system compromise. Public exploit code is currently available, increasing the likelihood of active exploitation. Despite previous hardening efforts in related endpoints via PR #1530 and commit 5f99b4d82, this specific utility remained unprotected. The vendor has not responded to disclosure attempts, leaving affected systems at risk without a formal vendor-supplied patch.",
"technicalDetails": "The vulnerability is a classic path traversal flaw located in the zipJsonLinesData function within the packages/api/src/utility/zipJsonLinesData.js file of the DbGate API. The root cause is the improper validation of user-supplied input provided to the filePath argument. The application fails to sanitize or restrict this path, allowing an attacker to supply directory traversal sequences (such as ../) to access files or directories outside of the intended export directory. While PR #1530 and commit 5f99b4d82 were implemented in earlier versions (7.2.5) to harden other export endpoints by introducing the checkSecureExportFilePath function, this specific utility endpoint was omitted from that security control, leaving it exposed.\nThe attack flow involves an attacker sending a specially crafted request to the Create Connection Endpoint where the filePath parameter is manipulated. By injecting path traversal sequences, an attacker can coerce the application to process or return files based on arbitrary file system paths. Because the endpoint does not perform an effective check on the resolved absolute path, the file system API processes the request relative to the root or the process execution directory, bypassing intended logical constraints. This allows for reading files the application process has permissions to access.\nThe exploitation of this vulnerability is remote and does not necessarily require complex setup, as functional exploit code is available in the public domain. The impact is significant: post-exploitation, an attacker could potentially retrieve sensitive configuration files, database credentials, or system data, depending on the service account's permissions. Since the vulnerability resides within an API endpoint, it is exposed to any network actor capable of interacting with the DbGate service. The lack of input normalization allows the underlying OS to interpret traversal characters, resulting in a successful traversal. Without the application of a secure path validation function, the system is unable to distinguish between legitimate user-requested files and malicious attempts to traverse the directory structure."
}