Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
- Severity:
- High
Description
DbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized functionName parameter in the /runners/load-reader endpoint. The require = null mitigation is trivially bypassed via dynamic import().
Recommendation
Update the dbgate-api package to the latest compatible version. Followings are version details:
- Affected version(s): <= 7.1.8
- Patched version(s): 7.1.9
References
Related Issues
- DbGate: Remote Code Execution via functionName injection in loadReader endpoint - CVE-2026-48017
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability - CVE-2026-41264
You might also like:
- Tags:
- npm
- dbgate-api
Anything's wrong? Let us know Last updated on June 05, 2026


