lowCVSS 3.5Vulnerability

CVE-2026-6216

A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/web/src/icons/FontIcon.svelte of the component SVG Icon String Handler. Such manipulation of the argument applicationIcon leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 7.1.5 mitigates this issue. It is advisable to upgrade the affected component.

Properties

summary
DbGate has cross site scripting via the SVG Icon String Handler component
severity
low
epss_score
0.00191
cvss_score
3.5
ghsa_published
2026-04-13T21:30:45Z
source_url
https://github.com/advisories/GHSA-j8j5-7r4h-vj2g
ghsa_updated
2026-04-14T23:37:07Z
ghsa_id
GHSA-j8j5-7r4h-vj2g
cve_id
CVE-2026-6216
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.08792

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/dbgate-web

AFFECTS (1)

[Software]npm/dbgate-web

Explore deeper with Ninja Signal's threat intelligence graph