<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – ArangoDB</title>
  <link>https://cvedaily.com/pages/tags/arangodb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/arangodb.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – ArangoDB</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-7715 – A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7715</guid>
    <pubDate>Mon, 04 May 2026 01:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-7715</strong></p>
  <p>A vulnerability has been found in ravenwits mcp-server-arangodb up to 0.4.7. This affects the function arango_backup of the file src/tools.ts of the component MCP Interface. Such manipulation of the argument outputDir leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early th…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25367 – ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25367</guid>
    <pubDate>Sun, 15 Feb 2026 14:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25367</strong></p>
  <p>ArangoDB Community Edition 3.4.2-1 contains multiple cross-site scripting vulnerabilities in the Aardvark web admin interface (index.html) through search, user management, and API parameters. Attackers can inject scripts via parameters in /_db/_system/_admin/aardvark/index.html to execute JavaScript in authenticated users' browsers.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36084 – cruddl is software for creating a GraphQL API for a database, using the GraphQL ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36084</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36084</guid>
    <pubDate>Thu, 08 Sep 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36084</strong></p>
  <p>cruddl is software for creating a GraphQL API for a database, using the GraphQL SDL to model a schema. If cruddl starting with version 1.1.0 and prior to versions 2.7.0 and 3.0.2 is used to generate a schema that uses `@flexSearchFulltext`, users of that schema may be able to inject arbitrary AQL queries that will be forwarded to and executed by ArangoDB. Schemas that do not use `@flexSearchFullt…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36084">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2021-25939 – In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25939</guid>
    <pubDate>Wed, 09 Feb 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2021-25939</strong></p>
  <p>In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25940 – In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Sessi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25940</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25940</guid>
    <pubDate>Tue, 16 Nov 2021 10:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25940</strong></p>
  <p>In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25940">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25938 – In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25938</guid>
    <pubDate>Mon, 24 May 2021 11:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25938</strong></p>
  <p>In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25938">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
