DbGate是DbGate组织开源的一个数据库管理器。 DbGate 7.1.8及之前版本存在安全漏洞,该漏洞源于JSON脚本运行器中的 参数存在代码注入,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | DbGate contains a remote code execution vulnerability exploitable by unauthenticated attackers. The /auth/login endpoint issues anonymous JWT tokens without credentials, and the /runners/start endpoint accepts JavaScript payloads that execute via Node.js child_process, allowing arbitrary command execution on the server. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-47668.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2026-47670 | 9.4 CRITICAL | DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code |
| CVE-2026-47669 | 9.3 CRITICAL | DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE |
No comments yet