Sceawere
Vulnerability Detail
CVE-2026-101069UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DbGate Path Traversal Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- n/a
- Product
- dbgate
- Attack Type
- Path Traversal
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-28T13:17:20.747Z",
"pubdate": "2026-09-28T13:17:20.747Z",
"executiveSummary": "A path traversal vulnerability exists in the exportModelSql function within the Export Handler component of DbGate versions up to 7.3.1. The vulnerability arises due to insufficient sanitization of the outputFile argument, which allows an attacker to manipulate file paths during the export process.\nThis vulnerability is exploitable remotely and does not require elevated privileges, presenting a significant security risk. By injecting path traversal sequences, a malicious actor can potentially read or overwrite sensitive files on the host system depending on the application's file handling logic.\nThe exposure of this flaw is aggravated by the availability of a public exploit. The vendor has remained unresponsive to disclosure attempts, leaving systems running affected versions without an official security patch.\nOrganizations utilizing DbGate are at risk of unauthorized filesystem access, which could lead to information disclosure or system compromise. Immediate implementation of compensating controls is recommended to mitigate the risk until the vendor addresses the underlying flaw.",
"technicalDetails": "The vulnerability resides in the exportModelSql function located in packages/api/src/controllers/databaseConnections.js. This function is responsible for handling database schema export requests and writing the resulting SQL output to the filesystem based on user-provided input.\nThe root cause is the improper validation and sanitization of the outputFile argument. The application fails to restrict or validate the file path provided by the user, allowing for the inclusion of directory traversal characters such as '../'. When the application processes this argument to determine the destination path for the exported SQL file, these traversal sequences are not filtered or neutralized.\nAn attacker can exploit this by crafting a request to the Export Handler with a manipulated outputFile parameter. By including multiple sequences of '../', an attacker can escape the intended directory and specify an arbitrary path on the filesystem. This allows the attacker to write files into restricted directories or, depending on the implementation of the file write operation, potentially overwrite existing system files.\nThe attack flow proceeds as follows: 1. The attacker identifies the endpoint that invokes the exportModelSql function. 2. The attacker constructs a malicious payload where the outputFile argument contains path traversal characters (e.g., ../../../etc/passwd or similar, depending on the target OS and application configuration). 3. The attacker submits the request to the DbGate API. 4. The server-side logic processes the input without adequate path validation. 5. The application attempts to write the export data to the attacker-supplied path. 6. The file is written to the unauthorized location, or the attacker succeeds in manipulating the filesystem state.\nThe exploitation is feasible remotely and does not necessitate prior authentication, making it a critical threat to exposed instances. Since the exploit is publicly available, the barrier to entry for attackers is minimal, allowing for automated exploitation attempts against vulnerable installations.\nThe post-exploitation impact includes unauthorized file manipulation, which can lead to further system compromise, such as overwriting configuration files, injecting malicious scripts into web-accessible directories, or potentially achieving remote code execution if the application environment allows for the execution of files placed by the attacker."
}