Missing Authorization Affecting github.com/getarcaneapp/arcane/backend/internal/services package, versions <1.19.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.39% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-GOLANG-GITHUBCOMGETARCANEAPPARCANEBACKENDINTERNALSERVICES-17748225
  • published1 Jul 2026
  • disclosed18 May 2026
  • creditUnknown

Introduced: 18 May 2026

CVE-2026-45625  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade github.com/getarcaneapp/arcane/backend/internal/services to version 1.19.0 or higher.

Overview

Affected versions of this package are vulnerable to Missing Authorization in the git repository management endpoints, which lack proper role-based access control. An attacker can gain unauthorized access to sensitive Git credentials, modify or delete repository configurations, and exfiltrate plaintext authentication tokens by repointing repository URLs to attacker-controlled hosts and triggering operations such as /test, /branches, or /files that cause the application to transmit decrypted credentials. This can also result in privilege escalation, supply-chain compromise, denial of service, and disclosure of private repository contents.

CVSS Base Scores

version 4.0
version 3.1