PT-2026-76942 · Arcadedb · Arcadedb
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ArcadeDB versions prior to 26.8.1
Description
An arbitrary file read issue exists in the OpenCypher
LOAD CSV FROM clause. Authenticated users with read query privileges can utilize the file:// protocol within LOAD CSV statements to access local files using the privileges of the server process, allowing the exfiltration of sensitive data through query responses.Recommendations
Update ArcadeDB to version 26.8.1 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arcadedb