Skip to content

Known CVE

Arcane <= 1.17.2 - Server-Side Request Forgery

Arcane <= 1.17.3 contains an unauthenticated server-side request forgery caused by lack of URL scheme and host validation in /api/templates/fetch endpoint, letting remote attackers perform SSRF, exploit requires no authentication.

CVE-2026-40242

High2026CVSS 7.2CWE-918

cve2026 · arcane · ssrf · oast · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website