Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8v3q-9vmx-36vc | DbGate: Unauthenticated Remote Code Execution via JSON Script Runner |
Fri, 24 Jul 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dbgate
Dbgate dbgate |
|
| Vendors & Products |
Dbgate
Dbgate dbgate |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch. | |
| Title | DbGate: Unauthenticated Remote Code Execution via JSON Script Runner | |
| Weaknesses | CWE-1188 CWE-20 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-23T18:34:44.584Z
Reserved: 2026-05-19T21:10:38.797Z
Link: CVE-2026-47668
Updated: 2026-07-23T18:34:16.366Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-23T23:45:02Z
Github GHSA