Intel

AIKIDO-2026-68889

arcadedb-engine is vulnerable to Path Traversal

Path TraversalCVE-2026-75842 Published 2 days ago

77

High Risk

This Affects:

JAVAarcadedb-engine
26.2.1 - 26.7.3
Fixed in 26.8.1
Are you affected? Scan for Free

TL;DR

LoadCSVStep opens a file:// URL or a bare filesystem path with FileInputStream and returns each line as a query row. OpenCypher does not require an administrative permission on that path, and the file URL setting defaults to enabled with an empty import directory, so a user who can run a read query on the server can read any file the server process can read. The fix requires the updateSecurity permission before that local file branch runs.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and a non-admin user can run OpenCypher on the server.

Background info

arcadedb-engine is vulnerable to Path Traversal in versions 26.2.1 - 26.7.3.

How to fix this

Upgrade the com.arcadedb:arcadedb-engine library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform