Vulnerabilities/

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

Severity:
High

Description

DbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized functionName parameter in the /runners/load-reader endpoint. The require = null mitigation is trivially bypassed via dynamic import().


Recommendation

Update the dbgate-api package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dbgate-api
Anything's wrong? Let us know Last updated on June 05, 2026