CVE-2026-101068 dbgate 路径遍历漏洞
影响攻击者可远程读取服务器任意文件
DbGate 7.3.1 及之前版本的 Create Connection Endpoint 组件中,zipJsonLinesData 函数未对 filePath 参数做安全校验,存在路径遍历漏洞。该漏洞可被远程利用,且公开利用代码已发布,厂商未作回应。
影响范围
DbGate 至 7.3.1(含)版本受影响;7.2.5 版本曾通过 checkSecureExportFilePath 加固其他导出端点,但遗漏了该端点。
漏洞详情
漏洞类型为路径遍历(Path Traversal)。zipJsonLinesData 函数在处理 filePath 参数时未过滤 ../ 等路径穿越字符,攻击者可构造恶意路径访问预期目录之外的文件。由于该端点可远程调用,攻击者无需本地访问即可触发。
利用条件与风险
利用前提是目标 DbGate 服务可被远程访问且相关接口可达;公开 PoC 已存在,实战中被扫描和利用的风险较高,可能导致敏感文件泄露。
修复建议
官方暂未发布修复版本,建议关注 DbGate 项目更新;临时缓解措施包括限制服务网络暴露、对 filePath 参数进行白名单校验或路径规范化过滤。
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.