CVE-2026-97225 | DbGate up to 7.2.5-beta.5 JSON Runner runners.js comment.text/script.schedule code injection (GHSA-rfx7-cmmf-7ff7)

SecurityVulns

A vulnerability classified as critical was found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument comment.text/script.schedule can lead to code injection.

This vulnerability appears as CVE-2026-97225. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.

This issue is distinct from CVE-2026-47668.VulDB Recent EntriesRead More