天下漏洞,尽知其名
MEDIUM

CVE-2026-101069 dbgate 路径遍历漏洞

影响远程攻击者可利用路径遍历写入任意文件

AI 研判

dbgate 7.3.1 及之前版本的导出功能存在路径遍历漏洞。攻击者可通过操纵 outputFile 参数,将导出文件写入预期目录之外的位置。该漏洞利用代码已公开,厂商未作回应。

影响范围

dbgate

dbgate 7.3.1 及更早版本(受影响组件为 packages/api/src/controllers/databaseConnections.js 中的 exportModelSql 函数)。

漏洞详情

漏洞类型为路径遍历(CWE-22)。exportModelSql 函数未对用户可控的 outputFile 参数做充分校验,攻击者可传入包含 ../ 的路径,使导出文件被写到任意目录。攻击可远程发起,且公开的利用方式已存在。

利用条件与风险

利用前提是攻击者能访问并调用导出接口并控制 outputFile 参数;由于利用代码已公开,实战中被扫描和利用的风险较高,可能导致任意文件写入甚至覆盖敏感文件。

修复建议

官方暂未发布修复版本,建议关注 dbgate 项目更新;临时缓解措施包括限制导出接口的访问权限、对 outputFile 参数进行路径规范化与白名单校验,禁止包含 ../ 等穿越字符。

原始情报

A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.