CVE-2026-101070 dbgate 路径遍历漏洞
影响远程攻击者可读取服务器任意文件
dbgate 7.3.1 及更早版本的 Files Endpoint 中,runners.js 的 files 函数未对 runid 参数做充分校验,存在路径穿越漏洞。该漏洞可被远程利用,且利用细节已公开。
影响范围
dbgate 7.3.1 及之前版本(具体受影响版本范围以官方公告为准,厂商未回应)。
漏洞详情
漏洞类型为路径穿越(Path Traversal)。成因是 packages/api/src/controllers/runners.js 中 files 函数对 runid 参数过滤不严,攻击者可通过构造包含 ../ 的路径跳出预期目录。攻击者可远程发送特制请求,读取服务器上的任意文件。
利用条件与风险
利用无需认证或仅需低权限(视部署配置而定),且 PoC 已公开,实战风险较高,可能导致敏感文件泄露。
修复建议
官方暂未发布修复版本,建议关注 dbgate 官方更新;临时缓解可限制 Files Endpoint 的访问权限、对 runid 参数进行严格校验或部署 WAF 拦截路径穿越请求。
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.