github.com/getarcaneapp/arcane/backend
Modern Docker Management, Designed for Everyone
Activity
- Latest release
- 3mo ago
- Total releases
- 20
- Cadence
- ~3 days
- Last 12 months
- 20
Reach
- Stars
- 7.4k
Details
- First release
- Feb 20, 2026
| Version | Released | |
|---|---|---|
v1.20.0
minor
1 CVE
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev |
v1.20.0
minor
Dependencies (55)
+ 47 more |
|
v1.19.5
patch
1 CVE
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.5
patch
Dependencies (55)
+ 47 more |
|
v1.19.4
patch
1 CVE
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.4
patch
Dependencies (54)
+ 46 more |
|
v1.19.3
patch
2 CVEs
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.3
patch
Dependencies (54)
+ 46 more |
|
v1.19.2
patch
2 CVEs
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.2
patch
Dependencies (54)
+ 46 more |
|
v1.19.1
patch
3 CVEs
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.1
patch
Dependencies (53)
+ 45 more |
|
v1.19.0
minor
3 CVEs
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.19.0
minor
Dependencies (54)
+ 46 more |
|
v1.18.1
patch
5 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.18.1
patch
Dependencies (53)
+ 45 more |
|
v1.18.0
minor
5 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.18.0
minor
Dependencies (53)
+ 45 more |
|
v1.17.4
patch
6 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.4
patch
Dependencies (53)
+ 45 more |
|
v1.17.3
patch
6 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.3
patch
Dependencies (53)
+ 45 more |
|
v1.17.2
patch
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.2
patch
Dependencies (53)
+ 45 more |
|
v1.17.1
patch
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.1
patch
Dependencies (54)
+ 46 more |
|
v1.17.0
minor
|
v1.17.0
minor
Dependencies (54)
+ 46 more |
|
v1.16.4
patch
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.16.4
patch
Dependencies (50)
+ 42 more |
|
v1.16.3
patch
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.16.3
patch
Dependencies (50)
+ 42 more |
|
v1.16.2
patch
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.16.2
patch
Dependencies (50)
+ 42 more |
|
v1.16.1
patch
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.16.1
patch
Dependencies (48)
+ 40 more |
|
v1.16.0
minor
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (48)
+ 40 more |
|
v1.15.3
initial
7 CVEs
CVE-2026-45627
GO-2026-5561
GHSA-q2pj-8v84-9mh5
Jun 25, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47125
GO-2026-5476
GHSA-jpjh-jm2p-39hh
Jun 25, 2026
Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.19.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45626
GO-2026-5292
GHSA-9mvm-4gwg-v8mp
Jun 25, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-47179
GO-2026-5308
GHSA-c3px-h233-h6fq
Jun 25, 2026
Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend Fixed in
1.19.4
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-42461
GO-2026-5340
GHSA-cxx3-hr75-4q96
Jun 25, 2026
Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) in github.com/getarcaneapp/arcane/backend Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. Fixed in
1.18.0
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-40242
GO-2026-5356
GHSA-ff24-4prj-gpmj
Jun 25, 2026
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint in github.com/getarcaneapp/arcane/backend Fixed in
1.17.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45625
GO-2026-5220
GHSA-7h26-hg47-p9hx
Jun 25, 2026
Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend Fixed in
1.19.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.15.3
initial
Dependencies (42)
+ 34 more |