---
id: CVE-2026-76225
title: >-
  ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in
  the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs
summary: >-
  ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in
  the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs.
  Authenticated attackers can craft LOAD CSV queries pointing to internal
  network…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-918
published: '2026-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76225'
references:
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-mmww-w3w3-6r86
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/arcadedb-before-server-side-request-forgery-via-load-csv
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-mmww-w3w3-6r86
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00354
epssPercentile: 0.26307
ingestedAt: '2026-09-08T21:11:12.284Z'
---

## Overview

ArcadeDB before 26.8.1 contains a server-side request forgery vulnerability in the OpenCypher LOAD CSV implementation that fails to validate HTTP/HTTPS URLs. Authenticated attackers can craft LOAD CSV queries pointing to internal network addresses or cloud metadata endpoints to make the ArcadeDB server fetch and return sensitive data from restricted services.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
