{"schema_version":"1.7.3","id":"GO-2026-4320","published":"2026-01-23T02:28:11Z","modified":"2026-03-03T04:57:52.721308Z","aliases":["CVE-2026-23520","GHSA-gjqq-6r35-w3r8"],"summary":"Arcane Has a Command Injection in Arcane Updater Lifecycle Labels That Enables RCE in github.com/getarcaneapp/arcane/backend","details":"Arcane Has a Command Injection in Arcane Updater Lifecycle Labels That Enables RCE in github.com/getarcaneapp/arcane/backend","affected":[{"package":{"name":"github.com/getarcaneapp/arcane/backend","ecosystem":"Go","purl":"pkg:golang/github.com/getarcaneapp/arcane/backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20260114065515-5a9c2f92e11f"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-4320.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/getarcaneapp/arcane/security/advisories/GHSA-gjqq-6r35-w3r8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23520"},{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/commit/5a9c2f92e11f86f8997da8c672844468f930b7e4"},{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/pull/1468"},{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/releases/tag/v1.13.0"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-4320"}}