GHSA-pj2x-fr4j-wrxqHighCVSS 6.5

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user...

Published
September 5, 2026
Last Modified
September 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.

🔗 References (8)