{"id":"CVE-2026-42461","aliases":["GHSA-cxx3-hr75-4q96","GO-2026-5340"],"url":"https://o3.security/vulnerability/CVE-2026-42461","summary":"Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl. `.env` secrets)","details":"### Summary\nFour `GET` endpoints under `/api/templates*` in Arcane's Huma backend are registered without any `Security` requirement, allowing any unauthenticated network client to list and read the full Compose YAML and `.env` content of every custom template stored in the instance. Because Arcane's UI exposes a \"Save as Template\" flow on the project / swarm-stack creation pages that persists the operator's *real* env content (database passwords, API keys, etc.) verbatim, this missing authorization is an unauthenticated read of operator secrets in practice — not a theoretical info-disclosure.\n\nThe frontend explicitly treats `/customize/templates/*` as an authenticated area (`PROTECTED_PREFIXES` in `frontend/src/lib/utils/redirect.util.ts`), and every CRUD operation (POST/PUT/DELETE) on the same paths requires a Bearer/API key, so this is a clear backend authorization gap, not intended public access.\n\n### Details\nAffected file: `backend/internal/huma/handlers/templates.go:194-228`.\n\nIn `RegisterTemplates`, four `huma.Register` calls have no `Security:` block:\n\n```go\n// templates.go\nhuma.Register(api, huma.Operation{\n    OperationID: \"listTemplatesPaginated\",\n    Method:      \"GET\",\n    Path:        \"/templates\",\n    ...\n    // <-- no Security\n}, h.ListTemplates)\n\nhuma.Register(api, huma.Operation{\n    OperationID: \"getAllTemplates\",\n    Method:      \"GET\",\n    Path:        \"/templates/all\",\n    ...\n}, h.GetAllTemplates)\n\nhuma.Register(api, huma.Operation{\n    OperationID: \"getTemplate\",\n    Method:      \"GET\",\n    Path:        \"/templates/{id}\",\n    ...\n}, h.GetTemplate)\n\nhuma.Register(api, huma.Operation{\n    OperationID: \"getTemplateContent\",\n    Method:      \"GET\",\n    Path:        \"/templates/{id}/content\",\n    ...\n}, h.GetTemplateContent)\n```\n\nArcane's auth bridge (`backend/internal/huma/middleware/auth.go:168-172`) only enforces authentication when the operation declares one of the security schemes (`BearerAuth` or `ApiKeyAuth`). With `Security` omitted, `parseSecurityRequirements` returns `isRequired=false` and the request flows through with no token check.\n\n`TemplateHandler.GetTemplateContent` (`templates.go:478-499`) calls `templateService.GetTemplateContentWithParsedData` (`backend/internal/services/template_service.go:1303-1347`), which returns the model's `Content`, `EnvContent`, parsed services, and parsed env-variable key/value pairs verbatim. The model `models.ComposeTemplate` (`backend/internal/models/template.go:15-16`) stores `Content` and `EnvContent` as plain `text` columns and has no owner / user binding.\n\n### Impact\n- Pre-auth confidentiality breach. An unauthenticated client on the same network (or through any path-unaware reverse proxy) recovers the full `envContent` of every locally-stored Compose template. Because the supported \"Save as Template\" workflow takes the operator's real env values verbatim, this commonly includes database passwords, registry tokens, third-party API keys (Stripe, Sentry, etc.), and OIDC client secrets.\n- Internal asset enumeration. `GET /api/templates` returns names, descriptions, tags, and registry metadata for every template, leaking what services the team runs internally and which compose files they reuse","published":"2026-05-09T03:30:13.371Z","modified":"2026-08-12T03:51:20.432622754Z","cvss":null,"epss":{"score":0.01051,"percentile":0.61265,"asOf":"2026-08-13"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/getarcaneapp/arcane/backend","fixedVersion":"1.18.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/getarcaneapp/arcane/releases/tag/v1.18.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42461.json"},{"type":"ADVISORY","url":"https://github.com/getarcaneapp/arcane/security/advisories/GHSA-cxx3-hr75-4q96"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42461"},{"type":"PACKAGE","url":"https://github.com/getarcaneapp/arcane"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.432622754Z"}}