<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 10:33:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-341013</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-341013</link>
      <description>EUVD-2026-341013</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-341013</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47670</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47670</link>
      <description>&lt;p&gt;DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47670</guid>
    </item>
    <item>
      <title>GHSA-wm5r-5qp3-5vxf — Authenticated Remote Code Execution via loadReader functionName code injection in DbGate</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wm5r-5qp3-5vxf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dbgate-api&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;DbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`.&lt;/p&gt;
&lt;p&gt;&amp;lt;br/&amp;gt;&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Code injection via `functionName` in loadReader**&lt;/p&gt;
&lt;p&gt;The `/runners/load-reader` endpoint interpolates the `functionName` parameter directly into a dynamically generated JavaScript script template without any sanitization:&lt;/p&gt;
&lt;p&gt;```javascript
// packages/api/src/controllers/runners.js (loadReader / loaderScriptTemplate)
const reader = await dbgateApi.${functionName}({...});
```&lt;/p&gt;
&lt;p&gt;By injecting a newline character into `functionName`, an attacker breaks out of the template expression and injects arbitrary JavaScript code. The injected code uses `await import(&amp;#39;child_process&amp;#39;)` to bypass the `require = null` mitigation (since `import()` is a language keyword, not a function that can be nullified), achieving arbitrary command execution as the process user (root in Docker).&lt;/p&gt;
&lt;p&gt;The June 2025 security fix ([commit cf3f95c](https://github.com/dbgate/dbgate/commit/cf3f95c952)) added `require = null` to the generated script, but this is trivially bypassed:&lt;/p&gt;
&lt;p&gt;```javascript
// Mitigation in generated script:
require = null;&lt;/p&gt;
&lt;p&gt;// Bypass via dynamic import (language keyword, cannot be nullified):
const { execSync } = await import(&amp;#39;child_process&amp;#39;);
exec…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: dbgate-api&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;DbGate is vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`.&lt;/p&gt;
&lt;p&gt;&amp;lt;br/&amp;gt;&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;**Code injection via `functionName` in loadReader**&lt;/p&gt;
&lt;p&gt;The `/runners/load-reader` endpoint interpolates the `functionName` parameter directly into a dynamically generated JavaScript script template without any sanitization:&lt;/p&gt;
&lt;p&gt;```javascript
// packages/api/src/controllers/runners.js (loadReader / loaderScriptTemplate)
const reader = await dbgateApi.${functionName}({...});
```&lt;/p&gt;
&lt;p&gt;By injecting a newline character into `functionName`, an attacker breaks out of the template expression and injects arbitrary JavaScript code. The injected code uses `await import(&amp;#39;child_process&amp;#39;)` to bypass the `require = null` mitigation (since `import()` is a language keyword, not a function that can be nullified), achieving arbitrary command execution as the process user (root in Docker).&lt;/p&gt;
&lt;p&gt;The June 2025 security fix ([commit cf3f95c](https://github.com/dbgate/dbgate/commit/cf3f95c952)) added `require = null` to the generated script, but this is trivially bypassed:&lt;/p&gt;
&lt;p&gt;```javascript
// Mitigation in generated script:
require = null;&lt;/p&gt;
&lt;p&gt;// Bypass via dynamic import (language keyword, cannot be nullified):
const { execSync } = await import(&amp;#39;child_process&amp;#39;);
exec…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wm5r-5qp3-5vxf</guid>
    </item>
  </channel>
</rss>
