Affected by GO-2026-5220
and 4 other vulnerabilities
GO-2026-5220: Arcane Backend: Missing admin authorization on git repository endpoints allows non-admin users to exfiltrate stored Git credentials and tamper with GitOps configs in github.com/getarcaneapp/arcane/backend
GO-2026-5292: Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter in github.com/getarcaneapp/arcane/backend
GO-2026-5308: Arcane Has an Authenticated Arbitrary Host File Read via Docker Compose Include Directives in github.com/getarcaneapp/arcane/backend
GO-2026-5476: Arcane: Missing admin authorization on global variables endpoint in github.com/getarcaneapp/arcane/backend
GO-2026-5561: Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend