Vulnerabilities/

dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration

Severity:
High

Description

A stored XSS vulnerability exists in DbGate because attacker-controlled SVG icon strings are rendered as raw HTML without sanitization.

Recommendation

Update the dbgate-web package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dbgate-web
Anything's wrong? Let us know Last updated on April 06, 2026