Loading HuntDB...

GHSA-rc98-whmj-qg8f

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself.

A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.

Related CVEs

Key Information

GHSA ID
GHSA-rc98-whmj-qg8f
Published
May 15, 2024 6:30 PM
Last Modified
May 15, 2024 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.