Dbgate · Dbgate · CVE-2026-101068
**Name of the Vulnerable Software and Affected Versions**
dbgate versions prior to 7.3.2
**Description**
A path traversal flaw exists in the Create Connection Endpoint component. The issue occurs within the `zipJsonLinesData()` function located in the `packages/api/src/utility/zipJsonLinesData.js` file. By manipulating the `filePath` argument, a remote attacker can perform path traversal, which allows accessing files or directories outside the intended folder. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
**Recommendations**
Update dbgate to version 7.3.2 or later.
As a temporary workaround, restrict access to the Create Connection Endpoint to minimize the risk of exploitation.