Executive brief
Arelle, an open-source platform for XBRL financial reporting, contains a critical security flaw in its web server component. An unauthenticated attacker can remotely force the server to download and execute malicious code. This could lead to a complete takeover of the server, theft of sensitive financial data, or disruption of reporting operations.
Technical details
Arelle's web server component fails to perform authentication or authorization on the '/rest/configure' REST endpoint. This endpoint accepts a 'plugins' query parameter which is passed directly to the application's plugin manager. An attacker can provide a URL pointing to a malicious Python script via this parameter. The server will subsequently download and execute the script within the context of the Arelle process, leading to full remote code execution (RCE). This vulnerability is addressed in version 2.39.10 by restricting webserver plugin loading.
Affected products
- Workiva Arelle before 2.39.10
Timeline
- 2026-04-24: patched: Version 2.39.10 released
- 2026-05-04: disclosed: Initial CVE publication