basekick-labs has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 4. The median CVSS is 8.3 (high). Most affected products: arc (2), github.com/basekick-labs/arc (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Products
- arc 2
- github.com/basekick-labs/arc 2
Worst active — by depth score
CVE-2026-48106High· 8.3Arc is an open, SQL-native time-series database for telemetry46CVE-2026-48105High· 8.3Arc is an open, SQL-native time-series database for telemetry46CVE-2026-47735HighArc is an open, SQL-native time-series database for telemetry41CVE-2026-55678MediumArc is an open, SQL-native time-series database for telemetry28
basekick-labs vulnerabilities
CVEs affecting basekick-labs, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-55678MediumArc is an open, SQL-native time-series database for telemetry
Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not confi…
CVE-2026-48105High· 8.3Arc is an open, SQL-native time-series database for telemetry
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals w…
CVE-2026-48106High· 8.3Arc is an open, SQL-native time-series database for telemetry
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode)…
CVE-2026-47735HighArc is an open, SQL-native time-series database for telemetry
Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The …