Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hq22-48ph-vqch

Опубликовано: 02 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.7
CVSS3: 7.5

Описание

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

EPSS

Процентиль: 12%
0.00214
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
nvd
4 дня назад

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool.

EPSS

Процентиль: 12%
0.00214
Низкий

7.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306