Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/controllers/runners.js of the component JSON Runner. Executing a manipulation of the argument comment.text/script.schedule can lead to code injection. The attack may be performed from remote. Upgrading to version 7.2.5-beta.6 mitigates this issue. This patch is called 70e7b6b58e464d7a015ba16e8d7574b420ee4877. Upgrading the affected component is advised. This issue is distinct from CVE-2026-47668. | |
| Title | DbGate JSON Runner runners.js code injection | |
| First Time appeared |
Dbgate
Dbgate dbgate |
|
| Weaknesses | CWE-74 CWE-94 |
|
| CPEs | cpe:2.3:a:dbgate:dbgate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dbgate
Dbgate dbgate |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-24T15:00:12.165Z
Reserved: 2026-09-24T09:53:17.836Z
Link: CVE-2026-97225
No data.
Status : Deferred
Published: 2026-09-24T16:17:28.880
Modified: 2026-09-24T16:17:29.040
Link: CVE-2026-97225
No data.
OpenCVE Enrichment
No data.