๐Ÿ” CVE Alert

CVE-2026-47669

UNKNOWN 0.0

DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.

CWE CWE-22
Vendor dbgate
Product dbgate
Published Jul 23, 2026
Stay Ahead of the Next One

Get instant alerts for dbgate dbgate

Be the first to know when new unknown vulnerabilities affecting dbgate dbgate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

dbgate / dbgate
< 7.1.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dbgate/dbgate/security/advisories/GHSA-h535-j5hr-mv56 github.com: https://github.com/dbgate/dbgate/releases/tag/v7.1.9