Arc
by Arc
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45489 | Cri | 0.64 | 9.8 | 0.01 | Sep 20, 2024 | Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the… | ||
| CVE-2024-52928 | Cri | 0.62 | 9.6 | 0.00 | Jun 26, 2025 | Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website. | ||
| CVE-2012-5872 | Cri | 0.57 | 9.8 | 0.01 | Apr 26, 2023 | ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause. | ||
| CVE-2023-5936 | Hig | 0.51 | 7.8 | 0.00 | May 15, 2024 | On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges. | ||
| CVE-2025-14812 | Hig | 0.49 | 7.5 | 0.00 | Dec 19, 2025 | ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk. | ||
| CVE-2026-2378 | Hig | 0.48 | 7.4 | 0.00 | Mar 20, 2026 | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | ||
| CVE-2025-14809 | Hig | 0.48 | 7.4 | 0.00 | Dec 19, 2025 | ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | ||
| CVE-2026-47735 | hig | 0.39 | — | 0.00 | Jun 8, 2026 | ### Summary Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family — `read_csv_auto`, `read_csv`, `read_json`, `read_json_auto`, `read_text`,… | ||
| CVE-2015-9275 | Med | 0.35 | 5.3 | 0.02 | Jan 7, 2019 | ARC 5.21q allows directory traversal via a full pathname in an archive file. | ||
| CVE-2005-2992 | 0.00 | — | 0.00 | Oct 13, 2005 | arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945. | |||
| CVE-2005-2945 | 0.00 | — | 0.00 | Sep 16, 2005 | arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c). |
- risk 0.64cvss 9.8epss 0.01
Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), it is possible to create or update a boost using another user's ID. This installs the boost in the…
- risk 0.62cvss 9.6epss 0.00
Arc before 1.26.1 on Windows has a bypass issue in the site settings that allows websites (with previously granted permissions) to add new permissions when the user clicks anywhere on the website.
- risk 0.57cvss 9.8epss 0.01
ARC (aka ARC2) through 2011-12-01 allows blind SQL Injection in getTriplePatternSQL in ARC2_StoreSelectQueryHandler.php via comments in a SPARQL WHERE clause.
- risk 0.51cvss 7.8epss 0.00
On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.
- risk 0.49cvss 7.5epss 0.00
ArcSearch for iOS versions prior to 1.45.2 could display a different domain in the address bar than the content being shown after an iframe-triggered URI-scheme navigation, increasing spoofing risk.
- risk 0.48cvss 7.4epss 0.00
ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- risk 0.48cvss 7.4epss 0.00
ArcSearch for Android versions prior to 1.12.6 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content.
- risk 0.39cvss —epss 0.00
### Summary Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family — `read_csv_auto`, `read_csv`, `read_json`, `read_json_auto`, `read_text`,…
- risk 0.35cvss 5.3epss 0.02
ARC 5.21q allows directory traversal via a full pathname in an archive file.
- CVE-2005-2992Oct 13, 2005risk 0.00cvss —epss 0.00
arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.
- CVE-2005-2945Sep 16, 2005risk 0.00cvss —epss 0.00
arc 5.21j and earlier create temporary files with world-readable permissions, which allows local users to read sensitive information from files created by (1) arc (arc.c) or (2) marc (marc.c).