<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T13:51:49.064670+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-341013</id>
    <title>EUVD-2026-341013</title>
    <updated>2026-10-06T13:51:49.121035+00:00</updated>
    <content>EUVD-2026-341013</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-341013"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47670</id>
    <title>fkie_cve-2026-47670</title>
    <updated>2026-10-06T13:51:49.121076+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-47670"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wm5r-5qp3-5vxf</id>
    <title>GHSA-wm5r-5qp3-5vxf — Authenticated Remote Code Execution via loadReader functionName code injection in DbGate</title>
    <updated>2026-10-06T13:51:49.121110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: dbgate-api</p>
<p>### Summary</p>
<p>DbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`.</p>
<p>&lt;br/&gt;</p>
<p>### Details</p>
<p>**Code injection via `functionName` in loadReader**</p>
<p>The `/runners/load-reader` endpoint interpolates the `functionName` parameter directly into a dynamically generated JavaScript script template without any sanitization:</p>
<p>```javascript
// packages/api/src/controllers/runners.js (loadReader / loaderScriptTemplate)
const reader = await dbgateApi.${functionName}({...});
```</p>
<p>By injecting a newline character into `functionName`, an attacker breaks out of the template expression and injects arbitrary JavaScript code. The injected code uses `await import('child_process')` to bypass the `require = null` mitigation (since `import()` is a language keyword, not a function that can be nullified), achieving arbitrary command execution as the process user (root in Docker).</p>
<p>The June 2025 security fix ([commit cf3f95c](https://github.com/dbgate/dbgate/commit/cf3f95c952)) added `require = null` to the generated script, but this is trivially bypassed:</p>
<p>```javascript
// Mitigation in generated script:
require = null;</p>
<p>// Bypass via dynamic import (language keyword, cannot be nullified):
const { execSync } = await import('child_process');
exec…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wm5r-5qp3-5vxf"/>
  </entry>
</feed>
