CVE-2026-101066 | dbgate up to 7.3.1 Archive Link Creation archive.js createLink linkedFolder path traversal

SecurityVulns

A vulnerability identified as critical has been detected in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal.

This vulnerability appears as CVE-2026-101066. The attack may be initiated remotely. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More