{"id":"GHSA-cxx3-hr75-4q96","summary":"Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets) ","details":"### Summary\nFour `GET` endpoints under `/api/templates*` in Arcane's Huma backend are registered without any `Security` requirement, allowing any unauthenticated network client to list and read the full Compose YAML and `.env` content of every custom template stored in the instance. Because Arcane's UI exposes a \"Save as Template\" flow on the project / swarm-stack creation pages that persists the operator's *real* env content (database passwords, API keys, etc.) verbatim, this missing authorization is an unauthenticated read of operator secrets in practice — not a theoretical info-disclosure.\n\nThe frontend explicitly treats `/customize/templates/*` as an authenticated area (`PROTECTED_PREFIXES` in `frontend/src/lib/utils/redirect.util.ts`), and every CRUD operation (POST/PUT/DELETE) on the same paths requires a Bearer/API key, so this is a clear backend authorization gap, not intended public access.\n\n### Details\nAffected file: `backend/internal/huma/handlers/templates.go:194-228`.\n\nIn `RegisterTemplates`, four `huma.Register` calls have no `Security:` block:\n\n```go\n// templates.go\nhuma.Register(api, huma.Operation{\n    OperationID: \"listTemplatesPaginated\",\n    Method:      \"GET\",\n    Path:        \"/templates\",\n    ...\n    // \u003c-- no Security\n}, h.ListTemplates)\n\nhuma.Register(api, huma.Operation{\n    OperationID: \"getAllTemplates\",\n    Method:      \"GET\",\n    Path:        \"/templates/all\",\n    ...\n}, h.GetAllTemplates)\n\nhuma.Register(api, huma.Operation{\n    OperationID: \"getTemplate\",\n    Method:      \"GET\",\n    Path:        \"/templates/{id}\",\n    ...\n}, h.GetTemplate)\n\nhuma.Register(api, huma.Operation{\n    OperationID: \"getTemplateContent\",\n    Method:      \"GET\",\n    Path:        \"/templates/{id}/content\",\n    ...\n}, h.GetTemplateContent)\n```\n\nArcane's auth bridge (`backend/internal/huma/middleware/auth.go:168-172`) only enforces authentication when the operation declares one of the security schemes (`BearerAuth` or `ApiKeyAuth`). With `Security` omitted, `parseSecurityRequirements` returns `isRequired=false` and the request flows through with no token check.\n\n`TemplateHandler.GetTemplateContent` (`templates.go:478-499`) calls `templateService.GetTemplateContentWithParsedData` (`backend/internal/services/template_service.go:1303-1347`), which returns the model's `Content`, `EnvContent`, parsed services, and parsed env-variable key/value pairs verbatim. The model `models.ComposeTemplate` (`backend/internal/models/template.go:15-16`) stores `Content` and `EnvContent` as plain `text` columns and has no owner / user binding.\n\n### Impact\n- Pre-auth confidentiality breach. An unauthenticated client on the same network (or through any path-unaware reverse proxy) recovers the full `envContent` of every locally-stored Compose template. Because the supported \"Save as Template\" workflow takes the operator's real env values verbatim, this commonly includes database passwords, registry tokens, third-party API keys (Stripe, Sentry, etc.), and OIDC client secrets.\n- Internal asset enumeration. `GET /api/templates` returns names, descriptions, tags, and registry metadata for every template, leaking what services the team runs internally and which compose files they reuse","aliases":["CVE-2026-42461","GO-2026-5340"],"modified":"2026-06-25T19:56:25.442774763Z","published":"2026-04-30T20:55:26Z","database_specific":{"nvd_published_at":"2026-05-09T04:16:26Z","cwe_ids":["CWE-862"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-30T20:55:26Z"},"references":[{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/security/advisories/GHSA-cxx3-hr75-4q96"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42461"},{"type":"PACKAGE","url":"https://github.com/getarcaneapp/arcane"},{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/releases/tag/v1.18.0"}],"affected":[{"package":{"name":"github.com/getarcaneapp/arcane/backend","ecosystem":"Go","purl":"pkg:golang/github.com/getarcaneapp/arcane/backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.18.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-cxx3-hr75-4q96/GHSA-cxx3-hr75-4q96.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}