Executive brief
DbGate is a database management tool used to connect to and administer various database systems. A security flaw in its file extraction process allows an attacker to write malicious files anywhere on the server's filesystem. In common setups, this can lead to a complete takeover of the application and the underlying server, potentially exposing sensitive database credentials and customer data.
Technical details
A 'Zip Slip' path traversal vulnerability exists in the `unzipDirectory()` function within `packages/api/src/shell/unzipDirectory.js`. The function fails to validate that extracted file paths remain within the intended output directory, allowing a malicious ZIP archive containing `../` sequences to write files to arbitrary locations. In default Docker deployments, the application runs as root and uses a 'none' authentication provider that issues JWT tokens without credentials. An attacker can exploit this by uploading a crafted ZIP and triggering the unzip endpoint to achieve remote code execution (e.g., by writing to `/etc/cron.d/`). The issue is fixed in version 7.1.9.
Affected products
- DbGate DbGate <= 7.1.8
Timeline
- 2026-04-22: patched: Version 7.1.9 released
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-07-23: disclosed: CVE published to NVD