CVE-2026-101068 | dbgate up to 7.3.1 Create Connection Endpoint zipJsonLinesData.js zipJsonLinesData filePath path traversal
A vulnerability marked as critical has been reported in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal.
This vulnerability is known as CVE-2026-101068. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More