The SQL IMPORT DATABASE statement did not require administrative privileges and passed its source URL to the importer without validation. Any authenticated user with SQL command access (not only root/administrators) could therefore:
169.254.169.254) and internal-only services, and ingest the responses as queryable records./etc/passwd, credential files) by importing file:// paths, exposing their contents as records.The server administration endpoint (/api/v1/server) was already restricted to the root user and was not affected; the exposure was through the database SQL command/query endpoints (/api/v1/command, /api/v1/query).
A related lower-severity hardening gap (CWE-776): the XML importer did not disable DTD processing, leaving entity-expansion (Billion Laughs) possible.
integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java (no host allow-list for http(s); no path validation for file://), reached from engine/.../query/sql/parser/ImportDatabaseStatement.java.
IMPORT DATABASE now requires the administrative updateSecurity permission (no-op in embedded mode).SourceDiscovery: HTTP(S) hosts resolving to loopback / link-local / private (site-local) / wildcard / multicast addresses are blocked by default (arcadedb.server.security.importBlockLocalNetworks, default true), and an optional local-path allow-list (arcadedb.server.security.importAllowedLocalPaths) restricts file:// reads.Fixed in commit referenced by pull request #4422.
Restrict SQL command/query access to trusted administrative users; do not grant query access to untrusted users on servers that can reach sensitive networks or hold sensitive local files. Upgrading is strongly recommended.
Reported by Bin Luo (luob87709@gmail.com).
{
"cwe_ids": [
"CWE-22",
"CWE-776",
"CWE-918"
],
"github_reviewed": true,
"github_reviewed_at": "2026-07-16T20:05:56Z",
"nvd_published_at": null,
"severity": "HIGH"
}