天下漏洞,尽知其名
HIGH

CVE-2026-101066 dbgate 路径遍历漏洞

影响攻击者可远程读取服务器任意文件

AI 研判

DbGate 7.3.1 及之前版本的归档链接创建功能存在路径遍历漏洞。createLink 函数未对 linkedFolder 参数做充分校验,攻击者可构造恶意路径访问预期目录之外的文件。该漏洞利用方式已被公开披露。

影响范围

DbGate

DbGate 至 7.3.1 版本(含)受影响,更高版本是否修复暂无公开信息。

漏洞详情

漏洞位于 packages/api/src/controllers/archive.js 的 createLink 函数,属于路径遍历(CWE-22)。由于对 linkedFolder 参数缺乏规范化与边界校验,攻击者可借助 ../ 等序列跳出允许目录,读取或操作服务器上的敏感文件。攻击可远程发起,无需本地接触。

利用条件与风险

利用前提是攻击者能访问归档链接创建相关接口,通常需具备一定认证或可达该 API。由于 PoC 已公开且厂商未回应,实战中被扫描利用的风险较高。

修复建议

官方暂未发布修复版本或回应,建议关注 DbGate 官方更新;临时缓解可限制该 API 的网络访问、对 linkedFolder 参数做白名单与路径规范化校验,或暂时禁用归档链接创建功能。

原始情报

A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.