CVE-2026-47669
DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.
| CWE | CWE-22 |
| Vendor | dbgate |
| Product | dbgate |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for dbgate dbgate
Be the first to know when new unknown vulnerabilities affecting dbgate dbgate are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
dbgate / dbgate
< 7.1.9