Code Injection Vulnerability in DbGate JSON Runner Component
CVE-2026-97225

5.3MEDIUM

Key Information:

Vendor

DbGate

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-97225?

A code injection vulnerability exists in the DbGate JSON Runner component, specifically affecting the argument manipulation within the file packages/api/src/controllers/runners.js. An attacker could exploit this flaw by altering the comment.text/script.schedule argument, enabling them to execute arbitrary code remotely. It is essential for users to upgrade to version 7.2.5-beta.6, where this issue has been mitigated through a specific patch. Taking proactive measures by updating the affected component is highly recommended to safeguard against potential exploits.

Affected Version(s)

DbGate 7.2.5-beta.0

DbGate 7.2.5-beta.1

DbGate 7.2.5-beta.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZsZsec (VulDB User)
.