๐Ÿ” CVE Alert

CVE-2026-47735

UNKNOWN 0.0

Arc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checks

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family โ€” `read_csv_auto`, `read_csv`, `read_json`, `read_json_auto`, `read_text`, `read_blob`, `glob`, `parquet_metadata`, `parquet_schema`, `read_xlsx`, etc. โ€” was not blocked. RBAC table-reference extraction inspected only `FROM`/`JOIN` clauses, so scalar table functions in the `SELECT` list slipped past both layers. This is fixed in 2026.06.1 via a structural sandbox at the DuckDB layer. After lockdown, DuckDB refuses to open any file outside the allowlist and refuses further `INSTALL`/`LOAD`. Already-loaded extensions remain callable. Some workarounds are available. Restrict API access to known-trusted networks via firewall rules or, as a temporary mitigation, add `read_csv*`/`read_json*`/`glob` etc. to `dangerousSQLPattern` in `internal/api/query.go`.

CWE CWE-22 CWE-200 CWE-918
Vendor basekick-labs
Product arc
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for basekick-labs arc

Be the first to know when new unknown vulnerabilities affecting basekick-labs arc are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Basekick-Labs / arc
< 2026.06.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Basekick-Labs/arc/security/advisories/GHSA-p2j4-c4g6-rpf5 github.com: https://github.com/Basekick-Labs/arc/pull/442 github.com: https://github.com/Basekick-Labs/arc/commit/91bdc29d1a02178ccf8c66375eccf85203108dfb github.com: https://github.com/Basekick-Labs/arc/releases/tag/v26.06.1