Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
604929
AlmaLinux
4582
Alpaquita
8714
Alpine
4032
Android
3262
BellSoft Hardened Containers
406
Bitnami
6828
Chainguard
5435
CleanStart
713
CRAN
14
crates.io
2181
Debian
53931
Echo
3111
GHC
3
GIT
81418
GitHub Actions
49
Go
6437
Hackage
30
Hex
57
Julia
393
Linux
15361
Mageia
5860
Maven
6273
MinimOS
19599
npm
216921
NuGet
1621
opam
11
openEuler
6219
openSUSE
12357
OSS-Fuzz
3817
Packagist
5993
Pub
11
PyPI
18481
Red Hat
19086
Rocky Linux
2881
Root
11668
RubyGems
1922
SUSE
20099
SwiftURL
50
Ubuntu
51656
VSCode
18
Wolfi
3429
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g2jx-37x6-6438
PyPI/arcade-mcp-server
arcade-mcp-server Has Default Hardcoded Worker Secret That Allows Full Unauthorized Access to All HTTP MCP Worker Endpoints
02 Dec 2025
Fix available
Severity - 6.5 (Medium)
PyPI - OSV