CVE-2026-101069 | dbgate up to 7.3.1 Export databaseConnections.js exportModelSql outputFile path traversal

SecurityVulns

A vulnerability described as critical has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal.

This vulnerability is handled as CVE-2026-101069. The attack can be executed remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More