Junglewise Threat Intelligence

CVE-2026-47669: DbGate path traversal in unzipDirectory archive extraction

CVE-2026-47669 · Severity: critical · CVSS 4 · Published 2026-07-23

Technologies: DbGate. Vendors: DbGate.

Executive brief

DbGate is a database management tool used to connect to and administer various database systems. A security flaw in its file extraction process allows an attacker to write malicious files anywhere on the server's filesystem. In common setups, this can lead to a complete takeover of the application and the underlying server, potentially exposing sensitive database credentials and customer data.

Technical details

A 'Zip Slip' path traversal vulnerability exists in the `unzipDirectory()` function within `packages/api/src/shell/unzipDirectory.js`. The function fails to validate that extracted file paths remain within the intended output directory, allowing a malicious ZIP archive containing `../` sequences to write files to arbitrary locations. In default Docker deployments, the application runs as root and uses a 'none' authentication provider that issues JWT tokens without credentials. An attacker can exploit this by uploading a crafted ZIP and triggering the unzip endpoint to achieve remote code execution (e.g., by writing to `/etc/cron.d/`). The issue is fixed in version 7.1.9.

Affected products

  • DbGate DbGate <= 7.1.8

Timeline

  • 2026-04-22: patched: Version 7.1.9 released
  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-07-23: disclosed: CVE published to NVD

References

Related threats