The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Server-side Request Forgery (SSRF) vulnerabilities in an interactive lesson.
Start learningUpgrade github.com/basekick-labs/arc/internal/api to version 26.06.1 or higher.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the DuckDB I/O functions, which bypass RBAC table-level checks. An attacker can access arbitrary local files and potentially sensitive information by submitting crafted SQL queries that invoke functions such as read_csv_auto, read_json, or glob. This may also allow server-side request forgery if the httpfs extension is loaded, enabling access to internal network resources.
This vulnerability can be mitigated by restricting API access to trusted networks via firewall rules or by temporarily adding the affected DuckDB I/O functions to the denylist in the SQL validator.