Critical severity10.0NVD Advisory· Published Jul 23, 2026· Updated Jul 24, 2026
CVE-2026-47668
CVE-2026-47668
Description
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (POST /runners/start) allows remote code execution via code injection in the functionName parameter of JSON script assign commands. The functionName value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dbgate-servenpm | < 7.1.9 | 7.1.9 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.