arcadedb has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was July 2026 with 4. The median CVSS is 7.7 (high). Most affected products: com.arcadedb:arcadedb-engine (2), com.arcadedb:arcadedb-server (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- com.arcadedb:arcadedb-engine 2
- com.arcadedb:arcadedb-server 2
Worst active — by depth score
GHSA-48qw-824m-86prHigh· 7.7ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read42GHSA-x9f9-r4m8-9xc2HighArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)41GHSA-x8mg-6r4p-87pfHighArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization41GHSA-vwjc-v7x7-cm6gHighArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js41
arcadedb vulnerabilities
CVEs affecting arcadedb, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
GHSA-48qw-824m-86prHigh· 7.7ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
GHSA-x9f9-r4m8-9xc2HighArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)
GHSA-vwjc-v7x7-cm6gHighArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
GHSA-x8mg-6r4p-87pfHighArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization