PT-2026-32518 · Dbgate · Dbgate

Ngocnn97

·

Published

2026-04-13

·

Updated

2026-04-14

·

CVE-2026-6216

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DbGate versions prior to 7.1.5
Description A cross-site scripting issue exists in the SVG Icon String Handler component within the file packages/web/src/icons/FontIcon.svelte. Remote manipulation of the applicationIcon argument can lead to this issue.
Recommendations Upgrade to version 7.1.5.

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6216
GHSA-J8J5-7R4H-VJ2G

Affected Products

Dbgate