Arcane <= 1.17.3 contains an unauthenticated server-side request forgery caused by lack of URL scheme and host validation in /api/templates/fetch endpoint, letting remote attackers perform SSRF, exploit requires no authentication.
id: CVE-2026-40242
info:
name: Arcane <= 1.17.2 - Server-Side Request Forgery
author: 0x_Akoko
...