Sceawere

Vulnerability Detail

CVE-2026-101070UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DbGate Path Traversal Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
3h ago
Vendor
n/a
Product
dbgate
Attack Type
Path Traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T14:17:13.543Z",
  "pubdate": "2026-09-28T14:17:13.543Z",
  "executiveSummary": "A critical path traversal vulnerability exists in DbGate versions up to 7.3.1 within the Files Endpoint component.\nThe vulnerability originates from improper validation of the 'runid' argument in 'packages/api/src/controllers/runners.js'.\nAn unauthenticated, remote attacker can manipulate this argument to bypass directory restrictions and access unauthorized files on the underlying file system.\nThe impact includes unauthorized disclosure of sensitive data, configuration files, or other critical system resources depending on the process privileges of the DbGate application.\nThe vulnerability is actively exploitable via public disclosures, and the lack of vendor response exacerbates the risk for users running affected versions.\nGiven the remote nature of the exploit, organizations should prioritize restricting network access or implementing compensating controls to prevent unauthorized access to the affected endpoint.",
  "technicalDetails": "The vulnerability is located in the 'packages/api/src/controllers/runners.js' file, which acts as a controller for the Files Endpoint. The root cause is an insecure handling of user-supplied input provided via the 'runid' argument.\nIn the affected codebase, the 'runid' parameter is utilized to construct file paths for server-side operations without adequate sanitization or normalization. Specifically, the application fails to validate the input against path traversal sequences, such as '../' (dot-dot-slash) characters, which allows an attacker to escape the intended directory scope.\nThe exploitation flow begins with a remote attacker sending a crafted HTTP request to the vulnerable Files Endpoint. By injecting directory traversal characters into the 'runid' argument, the attacker forces the application's underlying filesystem API to resolve paths outside of the intended, restricted directory. For example, a payload such as '?runid=../../../../etc/passwd' could be used to read sensitive system files.\nBecause this functionality is exposed through the API, it is accessible to remote users without specific authentication constraints being enforced at the controller level for this path. Consequently, an attacker can perform arbitrary file reads, potentially leaking source code, environment variables, database credentials, or system-level configuration files.\nThe lack of robust input validation mechanisms—such as strict regex filtering or canonicalization of the path before resolution—permits the traversal. Once the malicious path is resolved, the application returns the contents of the target file in the response body. This represents a significant security failure, as the application effectively grants the attacker read access to any file accessible by the system user running the DbGate process.\nThe exploit is facilitated by the absence of a 'jail' or chroot-like environment, ensuring that the application processes maintain access to the broader filesystem scope. Given the public nature of the disclosure and the lack of vendor-provided patches, the attack surface remains wide open for deployment environments where the DbGate API is exposed to untrusted networks."
}
CVE-2026-101070: DbGate Path Traversal Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere