Vulnerabilities in Basekick-Labs
5 resultsVexday analysis
Basekick-Labs apresenta 4 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando descoberta recente de falhas. Nenhuma está sob ataque ativo (KEV) e não há críticas por CVSS, reduzindo o risco imediato. A fraqueza dominante é exposição de informações (CWE-200), sugerindo problemas de controle de acesso a dados sensíveis que demandam revisão arquitetural.
CVE-2026-55678MEDIUMArc: Unauthenticated cluster node admission when `cluster.shared_secret` is unsetEPSS 0.4%CVE-2026-48050HIGHArc: Unauthenticated access to Go debug pprof endpoints leaks runtime state and enables CPU-burn DoSEPSS 0.4%CVE-2026-47735HIGHArc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksEPSS 0.3%CVE-2026-48105HIGHArc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitiveEPSS 0.2%CVE-2026-48106HIGHArc Enterprise cluster replication accepts unauthenticated MsgReplicateSync messages, enabling cluster-wide data injection from any TLS-trusted peerEPSS 0.2%