DbGate: Remote Code Execution via functionName injection in loadReader endpoint
- Severity:
- High
Description
The POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation.
Recommendation
Update the dbgate-api package to the latest compatible version. Followings are version details:
- Affected version(s): <= 7.1.8
- Patched version(s): 7.1.9
References
Related Issues
- Authenticated Remote Code Execution via loadReader functionName code injection in DbGate - CVE-2026-47670
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
- Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified - CVE-2026-69255
- Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) - CVE-2026-73649
You might also like:
- Tags:
- npm
- dbgate-api
Anything's wrong? Let us know Last updated on July 08, 2026


