{"id":"GHSA-x9f9-r4m8-9xc2","summary":"ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)","details":"ScriptTriggerExecutor sets allowedPackages to java.lang.*, java.util.*, java.time.*, java.math.* (ScriptTriggerExecutor.java:56); trigger creation is gated only at UPDATE_SCHEMA (LocalSchema.createTrigger:636). Permitting java.lang.* host-class lookup lets a trigger script do Java.type(\"java.lang.Runtime\").getRuntime().exec(...) (or ProcessBuilder). The reflection denylist does not block Java.type host lookups, and allowCreateProcess(false) only restricts GraalVM's guest process API, not a host Runtime.exec reached through HostAccess.ALL.\n\nExploit: a user with UPDATE_SCHEMA (schema admin, strictly less than security admin) runs CREATE TRIGGER ... EXECUTE JAVASCRIPT '\u003cruntime.exec\u003e' and obtains OS RCE when the trigger fires.\n\nFix: remove java.lang.* (and narrow the rest) from the trigger allow-list; if host interop is needed, expose an explicit @HostAccess.Export API surface instead of whole packages; consider gating trigger creation at UPDATE_SECURITY. Prefer an allow-list (HostAccess.EXPLICIT) over the current denylist-over-HostAccess.ALL.\n\nRelated medium/low items to fold into the fix: IMPORT DATABASE SSRF via unfollowed-redirect re-validation (SourceDiscovery.java:113), BACKUP/EXPORT DATABASE missing authorization (BackupDatabaseStatement.java:56, ExportDatabaseStatement.java:52), chunked-transfer body-size DoS bypass (HttpServer.java:301,318-333), and no brute-force lockout on password auth (ServerSecurity.java:189-205).","aliases":["CVE-2026-67340"],"modified":"2026-08-02T03:56:46.660247356Z","published":"2026-07-16T20:15:36Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-16T20:15:36Z"},"references":[{"type":"WEB","url":"https://github.com/ArcadeData/arcadedb/security/advisories/GHSA-x9f9-r4m8-9xc2"},{"type":"PACKAGE","url":"https://github.com/ArcadeData/arcadedb"},{"type":"WEB","url":"https://github.com/ArcadeData/arcadedb/releases/tag/26.7.2"}],"affected":[{"package":{"name":"com.arcadedb:arcadedb-engine","ecosystem":"Maven","purl":"pkg:maven/com.arcadedb/arcadedb-engine"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.7.2"}]}],"versions":["21.10.1","21.10.2","21.11.1","21.12.1","21.9.1","21.9.1-beta","22.1.1","22.1.2","22.1.3","22.10.1","22.11.1","22.12.1","22.2.1","22.8.1","22.9.1","23.1.1","23.1.2","23.10.1","23.11.1","23.12.1","23.12.2","23.2.1","23.3.1","23.4.1","23.5.1","23.6.1","23.7.1","23.9.1","24.1.1","24.10.1","24.11.1","24.11.2","24.2.1","24.4.1","24.5.1","24.6.1","25.1.1","25.10.1","25.11.1","25.12.1","25.2.1","25.3.1","25.3.2","25.4.1","25.5.1","25.6.1","25.7.1","25.8.1","25.9.1","26.1.1","26.2.1","26.2.2","26.3.1","26.3.2","26.4.2","26.5.1","26.6.1","26.7.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-x9f9-r4m8-9xc2/GHSA-x9f9-r4m8-9xc2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}