CVE-2026-47670 is an authenticated Remote Code Execution (RCE) vulnerability in DbGate, a cross-platform database manager. Versions 7.1.8 and prior are affected. The vulnerability allows any user with valid DbGate credentials to execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation can be bypassed [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T20:17:08.357Z and has not been modified since then. The NVD entry is currently Deferred. This Critical vulnerability in DbGate, a cross-platform database manager, allows arbitrary file writes on the filesystem via a malicious ZIP file. The `unzipDirectory()` function in `packages/api/src/shell/un [truncated]
CVE-2026-48017 is a high-severity vulnerability in DbGate, a cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. This allows an authenticated user with basic access (no admin role, no run-shell-script permission required) to [truncated]