No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 24 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument comment.text/script.schedule can lead to code injection. The attack may be performed from remote. Upgrading to version 7.2.5-beta.6 mitigates this issue. This patch is called 70e7b6b58e464d7a015ba16e8d7574b420ee4877. Upgrading the affected component is advised. This issue is distinct from CVE-2026-47668. | |
| Title | DbGate JSON Runner runners.js code injection | |
| First Time appeared |
Dbgate
Dbgate dbgate |
|
| Weaknesses | CWE-74 CWE-94 |
|
| CPEs | cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dbgate
Dbgate dbgate |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-24T15:00:12.165Z
Reserved: 2026-09-24T09:53:17.836Z
Link: CVE-2026-97225
No data.
Status : Deferred
Published: 2026-09-24T16:17:28.880
Modified: 2026-09-24T16:17:29.040
Link: CVE-2026-97225
No data.
OpenCVE Enrichment
No data.