{
    "id": "CVE-2026-47668",
    "published": "2026-07-23 18:16:53",
    "last_modified": "2026-07-24 05:16:44",
    "cvss_score": "10.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-20",
    "description": "DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.",
    "epss_score": "0.03882",
    "epss_percentile": "0.89957",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-08 18:17:55",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (10), but no sign of active exploitation."
    },
    "products": [],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://github.com/dbgate/dbgate/releases/tag/v7.1.9",
        "https://github.com/dbgate/dbgate/security/advisories/GHSA-8v3q-9vmx-36vc",
        "https://github.com/runZeroInc/nuclei-templates/blob/main/http/vulnerabilities/dbgate-unauth-rce.yaml",
        "https://github.com/dbgate/dbgate/security/advisories/GHSA-8v3q-9vmx-36vc"
    ]
}