Description
A stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization.
Recommendation
Update the dbgate-web package to the latest compatible version. Followings are version details:
- Affected version(s): >= 7.0.0, < 7.1.5
- Patched version(s): 7.1.5
References
Could your website be exposed too?
SmartScanner can check your website for dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes - @tinacms/mdx - CVE-2026-55661
- Fabric.js Affected by Stored XSS via SVG Export - CVE-2026-27013
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - @haxtheweb/video-player - CVE-2026-46396
- Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover - CVE-2026-46396


