Server-side Request Forgery (SSRF) Affecting github.com/basekick-labs/arc/internal/api package, versions <26.06.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (23rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMBASEKICKLABSARCINTERNALAPI-17723784
  • published30 Jun 2026
  • disclosed8 Jun 2026
  • creditUnknown

Introduced: 8 Jun 2026

CVE-2026-47735  (opens in a new tab)
CWE-22  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade github.com/basekick-labs/arc/internal/api to version 26.06.1 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the DuckDB I/O functions, which bypass RBAC table-level checks. An attacker can access arbitrary local files and potentially sensitive information by submitting crafted SQL queries that invoke functions such as read_csv_auto, read_json, or glob. This may also allow server-side request forgery if the httpfs extension is loaded, enabling access to internal network resources.

Workaround

This vulnerability can be mitigated by restricting API access to trusted networks via firewall rules or by temporarily adding the affected DuckDB I/O functions to the denylist in the SQL validator.

CVSS Base Scores

version 4.0
version 3.1