VYPR
Critical severity10.0NVD Advisory· Published Jul 23, 2026· Updated Jul 24, 2026

CVE-2026-47668

CVE-2026-47668

Description

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (POST /runners/start) allows remote code execution via code injection in the functionName parameter of JSON script assign commands. The functionName value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
dbgate-servenpm
< 7.1.97.1.9

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.