Vulnerability GHSA-48qw-824m-86pr

High Risk
HIGH RISK
CVSS Score: 7.7
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 months ago
July 16, 2026 at 08:13 PM UTC
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
21.9.1 and 21.10.1 - 21.10.2 and 21.11.1 and 21.12.1 and 22.2.1 and 22.8.1 and 22.9.1 and 22.10.1 and 22.11.1 and 22.12.1 and 23.1.1 - 23.1.2 and 23.2.1 and 23.3.1 and 23.4.1 and 23.5.1 and 23.6.1 and 23.7.1 and 23.9.1 and 23.10.1 and 23.11.1 and 23.12.1 - 23.12.2 and 24.1.1 and 24.2.1 and 24.4.1 and 24.5.1 and 24.6.1 and 24.10.1 and 24.11.1 - 24.11.2 and 25.1.1 and 25.2.1 and 25.3.1 - 25.3.2 and 25.4.1 and 25.5.1 and 25.6.1 and 25.7.1 and 25.8.1 and 25.9.1 and 25.10.1 and 25.11.1 and 25.12.1 and 26.1.1 and 26.2.1 - 26.2.2 and 26.3.1 - 26.3.2 and 26.4.2 and 26.5.1 and 26.6.1
21.9.1 and 21.10.1 - 21.10.2 and 21.11.1 and 21.12.1 and 22.2.1 and 22.8.1 and 22.9.1 and 22.10.1 and 22.11.1 and 22.12.1 and 23.1.1 - 23.1.2 and 23.2.1 and 23.3.1 and 23.4.1 and 23.5.1 and 23.6.1 and 23.7.1 and 23.9.1 and 23.10.1 and 23.11.1 and 23.12.1 - 23.12.2 and 24.1.1 and 24.2.1 and 24.4.1 and 24.5.1 and 24.6.1 and 24.10.1 and 24.11.1 - 24.11.2 and 25.1.1 and 25.2.1 and 25.3.1 - 25.3.2 and 25.4.1 and 25.5.1 and 25.6.1 and 25.7.1 and 25.8.1 and 25.9.1 and 25.10.1 and 25.11.1 and 25.12.1 and 26.1.1 and 26.2.1 - 26.2.2 and 26.3.1 - 26.3.2 and 26.4.2 and 26.5.1 and 26.6.1

Summary

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

Details

Impact

A user holding only reader (read-only) privileges on a single database could execute arbitrary JVM code by sending a "language": "js" command to the POST /api/v1/command/{database} HTTP endpoint, and use it to read arbitrary files on the host filesystem (e.g. /etc/passwd, configuration files), outside the scope of the database itself.

Two cooperating defects made this possible:

  1. Missing authorization on the scripting path (CWE-863 / CWE-269). Polyglot script execution (js and other GraalVM languages) never went through the database authorization checks applied to SQL/Cypher, so any authenticated principal - regardless of database role - could run scripts.
  2. Sandbox whitelist bypass. The GraalVM sandbox restricts direct class lookups to a configured allowedPackages list, but a script could reach arbitrary classes by reflecting off the bound database object: database.getClass().getClassLoader().loadClass("java.io.File").

Process creation was already blocked (allowCreateProcess(false)), so the confirmed impact is host file read, not OS command execution. Confidentiality: High. Integrity/Availability: None.

This is a distinct entry point and root cause from CVE-2026-44221, CVE-2026-54076 and CVE-2026-54077, and is reproducible on builds that already contain those fixes.

Patches

The fix is applied in the engine so it covers every entry point (HTTP command, HA-forwarded commands, MCP analyze), not only the HTTP handler:

  • Polyglot script execution now requires the updateSecurity database-administrator permission on command, analyze and registerFunctions. The check runs on the request thread that carries the authenticated user and is a no-op in embedded mode and internal/system contexts (schema load, HA replication apply).
  • The GraalVM host-access policy now denies access to java.lang.Class, java.lang.ClassLoader and java.lang.reflect members, closing the reflection escape that bypassed allowedPackages - even for authorized administrators - while leaving normal method calls on bound objects and explicit Java.type(...) lookups (governed by allowedPackages) working.

Workarounds

Until upgraded, do not grant command/query access on the HTTP API to untrusted users, and treat any account that can reach /api/v1/command as capable of code execution. Note that after the fix, non-administrator accounts can no longer run js/polyglot scripts over HTTP.

Credit

Reported by @kyojune76.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
2 months ago
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
21.9.1 and 21.10.1 - 21.10.2 and 21.11.1 and 21.12.1 and 22.2.1 and 22.8.1 and 22.9.1 and 22.10.1 and 22.11.1 and 22.12.1 and 23.1.1 - 23.1.2 and 23.2.1 and 23.3.1 and 23.4.1 and 23.5.1 and 23.6.1 and 23.7.1 and 23.9.1 and 23.10.1 and 23.11.1 and 23.12.1 - 23.12.2 and 24.1.1 and 24.2.1 and 24.4.1 and 24.5.1 and 24.6.1 and 24.10.1 and 24.11.1 - 24.11.2 and 25.1.1 and 25.2.1 and 25.3.1 - 25.3.2 and 25.4.1 and 25.5.1 and 25.6.1 and 25.7.1 and 25.8.1 and 25.9.1 and 25.10.1 and 25.11.1 and 25.12.1 and 26.1.1 and 26.2.1 - 26.2.2 and 26.3.1 - 26.3.2 and 26.4.2 and 26.5.1 and 26.6.1 and 26.7.1 GHSA-x8mg-6r4p-87pf
21.9.1 and 21.10.1 - 21.10.2 and 21.11.1 and 21.12.1 and 22.2.1 and 22.8.1 and 22.9.1 and 22.10.1 and 22.11.1 and 22.12.1 and 23.1.1 - 23.1.2 and 23.2.1 and 23.3.1 and 23.4.1 and 23.5.1 and 23.6.1 and 23.7.1 and 23.9.1 and 23.10.1 and 23.11.1 and 23.12.1 - 23.12.2 and 24.1.1 and 24.2.1 and 24.4.1 and 24.5.1 and 24.6.1 and 24.10.1 and 24.11.1 - 24.11.2 and 25.1.1 and 25.2.1 and 25.3.1 - 25.3.2 and 25.4.1 and 25.5.1 and 25.6.1 and 25.7.1 and 25.8.1 and 25.9.1 and 25.10.1 and 25.11.1 and 25.12.1 and 26.1.1 and 26.2.1 - 26.2.2 and 26.3.1 - 26.3.2 and 26.4.2 and 26.5.1 and 26.6.1 and 26.7.1 GHSA-x8mg-6r4p-87pf
Critical
4 months ago
ArcadeDB vulnerable to cross-database authorization bypass and unsecured newly-created databases
21.10.1 - 21.10.2 and 21.11.1 and 21.12.1 and 22.2.1 and 22.8.1 and 22.9.1 and 22.10.1 and 22.11.1 and 22.12.1 and 23.1.1 - 23.1.2 and 23.2.1 and 23.3.1 and 23.4.1 and 23.5.1 and 23.6.1 and 23.7.1 and 23.9.1 and 23.10.1 and 23.11.1 and 23.12.1 - 23.12.2 and 24.1.1 and 24.2.1 and 24.4.1 and 24.5.1 and 24.6.1 and 24.10.1 and 24.11.1 - 24.11.2 and 25.1.1 and 25.2.1 and 25.3.1 - 25.3.2 and 25.4.1 and 25.5.1 and 25.6.1 and 25.7.1 and 25.8.1 and 25.9.1 and 25.10.1 and 25.11.1 and 25.12.1 and 26.1.1 and 26.2.1 - 26.2.2 and 26.3.1 - 26.3.2 GHSA-fxc7-fm93-6q77
21.10.1 - 21.10.2 and 21.11.1 and 21.12.1 and 22.2.1 and 22.8.1 and 22.9.1 and 22.10.1 and 22.11.1 and 22.12.1 and 23.1.1 - 23.1.2 and 23.2.1 and 23.3.1 and 23.4.1 and 23.5.1 and 23.6.1 and 23.7.1 and 23.9.1 and 23.10.1 and 23.11.1 and 23.12.1 - 23.12.2 and 24.1.1 and 24.2.1 and 24.4.1 and 24.5.1 and 24.6.1 and 24.10.1 and 24.11.1 - 24.11.2 and 25.1.1 and 25.2.1 and 25.3.1 - 25.3.2 and 25.4.1 and 25.5.1 and 25.6.1 and 25.7.1 and 25.8.1 and 25.9.1 and 25.10.1 and 25.11.1 and 25.12.1 and 26.1.1 and 26.2.1 - 26.2.2 and 26.3.1 - 26.3.2 GHSA-fxc7-fm93-6q77
View all vulnerabilities for these packages

Timeline

Published
2 months ago
July 16, 2026 at 08:13 PM UTC
Fixed (26.7.1)
Unknown
Unknown
Last Modified
12 hours ago
September 16, 2026 at 03:56 AM UTC