Junglewise Threat Intelligence

CVE-2026-45626: Arcane OS command injection in volume browser

CVE-2026-45626 · Severity: medium · CVSS 6.3 · Published 2026-05-29

Technologies: Getarcaneapp Arcane, github.com/getarcaneapp/arcane/backend (Go), Arcane backend. Vendors: Go, Arcane.

Executive brief

Arcane, a management interface for Docker environments, contains a security flaw in its volume browsing feature. An authenticated user can use specially crafted file paths to run unauthorized commands inside a temporary container used by the system. While the commands are restricted to an isolated environment without network access, an attacker could still view sensitive file data or delete volume contents that they should not be able to modify.

Technical details

An OS command injection vulnerability exists in the `GET /environments/{id}/volumes/{volumeName}/browse` endpoint of Arcane. The `path` query parameter is processed by `sanitizeBrowsePathInternal`, which filters directory traversal (`../`) but fails to strip shell metacharacters like `$()` or backticks. The resulting string is passed to `sh -c` via `fmt.Sprintf` and `strconv.Quote`. Because `strconv.Quote` only escapes Go-specific characters, the shell still performs command substitution. An authenticated attacker can execute commands inside the helper container; although the container lacks network access and privileged status, command output is reflected in 500 error responses, enabling data exfiltration from the mounted volume. Additionally, the same sanitization flaw allows for recursive volume deletion via the DELETE method.

Affected products

  • getarcaneapp Arcane <= 1.18.1

Timeline

  • 2026-05-11: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: CVE published to NVD

References

Related threats