Impact
ArcadeDB versions prior to 26.8.1 have a server‑side request forgery flaw within the OpenCypher LOAD CSV implementation; the system does not validate HTTP or HTTPS URLs supplied in a LOAD CSV query. An attacker who authenticates to the database can craft a LOAD CSV statement that points to internal network resources or cloud metadata endpoints, causing the ArcadeDB server to fetch and return data from those restricted services. The primary consequence is the disclosure of sensitive information that should be restricted to internal consumers, thereby compromising confidentiality.
Affected Systems
The vulnerability affects ArcadeData's ArcadeDB database product for all releases earlier than 26.8.1. Only environments where the loading of CSV data is enabled are impacted.
Risk and Exploitability
The CVSS score of 8.3 classifies this as a high‑severity flaw. Although the EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, the attack requires only authentication and does not need additional exploitation factors; the attacker can obtain internal data using standard database queries. Because the flaw directly leverages an exposed command and the server performs outbound HTTP(S) requests without validation, the potential damage is significant if an attacker can identify valuable internal resources or metadata endpoints. The low barrier to use makes mitigation a priority.
OpenCVE Enrichment