PatchSiren

dbgate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL dbgate CVE published 2026-07-23

CVE-2026-47670

CVE-2026-47670 is an authenticated Remote Code Execution (RCE) vulnerability in DbGate, a cross-platform database manager. Versions 7.1.8 and prior are affected. The vulnerability allows any user with valid DbGate credentials to execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation can be bypassed [truncated]

CRITICAL dbgate CVE published 2026-07-23

CVE-2026-47669

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T20:17:08.357Z and has not been modified since then. The NVD entry is currently Deferred. This Critical vulnerability in DbGate, a cross-platform database manager, allows arbitrary file writes on the filesystem via a malicious ZIP file. The `unzipDirectory()` function in `packages/api/src/shell/un [truncated]

HIGH dbgate CVE published 2026-06-15

CVE-2026-48017

CVE-2026-48017 is a high-severity vulnerability in DbGate, a cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. This allows an authenticated user with basic access (no admin role, no run-shell-script permission required) to [truncated]