Περιγραφή
Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project-s compose file before any path-traversal validation runs. Because ProjectService.CreateProject writes attacker-supplied compose content to disk without validating include paths, an authenticated user can create a project whose compose file declares include: [-../../../../etc/passwd-], then read the include via the project file API. The result is arbitrary read of any file readable by the Arcane backend process, including /app/data/arcane.db (the SQLite database containing every user-s password hash and API key), enabling escalation to admin and, via Arcane-s Docker control plane, RCE on the host. This vulnerability is fixed in 1.19.4.
- Δημοσίευση
- 2026-05-29 18:17:12
- Επηρεαζόμενες εκδόσεις
- <1.19.4
- Τύπος
- Core software
- Τελευταία τροποποίηση
- 2026-07-25 10:10:00
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N