{"schema_version":"1.9.0","id":"CVE-2026-23520","published":"2026-01-15T19:20:22.434Z","modified":"2026-08-12T03:51:19.504161381Z","aliases":["GHSA-gjqq-6r35-w3r8","GO-2026-4320"],"related":["SUSE-SU-2026:0292-1","openSUSE-SU-2026:21483-1"],"summary":"Arcane has a Command Injection in Arcane Updater Lifecycle Labels Enables RCE","details":"Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcane.lifecycle.post-update that allowed defining a command to run before or after a container update. The label value is passed directly to /bin/sh -c without sanitization or validation. Because any authenticated user (not limited to administrators) can create projects through the API, an attacker can create a project that specifies one of these lifecycle labels with a malicious command. When an administrator later triggers a container update (either manually or via scheduled update checks), Arcane reads the lifecycle label and executes its value as a shell command inside the container. This vulnerability is fixed in 1.13.0.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/getarcaneapp/arcane","events":[{"introduced":"0"},{"fixed":"2e32ef4443676edcceb26c8e41f637974f0041c8"},{"fixed":"5a9c2f92e11f86f8997da8c672844468f930b7e4"}],"database_specific":{"cpe":"cpe:2.3:a:arcane:arcane:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.13.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.12.2","v1.12.1","v1.12.0","v1.11.3","v1.11.2","v1.11.1","v1.11.0","v1.10.1","v1.10.0","v1.9.0","v1.8.1","v1.8.0","v1.7.1","v1.7.0","v1.6.0","v1.5.2","v1.5.1","v1.5.0","v1.4.0","v1.3.0","v1.2.2","v1.2.1","v1.2.0","v1.1.0","v1.0.2","v1.0.1","v1.0.0","v0.15.1","v0.15.0","v0.14.0","v0.13.1","v0.13.0","v0.12.0","v0.11.1","v0.11.0","v0.10.0","v0.9.2","v0.9.1","v0.9.0","v0.8.0","v0.7.1","v0.7.0","v0.6.0","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.2.0","v0.1.1","v0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23520.json"}}],"references":[{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/releases/tag/v1.13.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23520.json"},{"type":"ADVISORY","url":"https://github.com/getarcaneapp/arcane/security/advisories/GHSA-gjqq-6r35-w3r8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23520"},{"type":"FIX","url":"https://github.com/getarcaneapp/arcane/commit/5a9c2f92e11f86f8997da8c672844468f930b7e4"},{"type":"FIX","url":"https://github.com/getarcaneapp/arcane/pull/1468"}],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23520.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H"}]}