—
GO-2026-5561
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend
Quick fix
GO-2026-5561 — github.com/getarcaneapp/arcane/backend: upgrade to the fixed version with the command below.
go get github.com/getarcaneapp/arcane/backend@v1.19.0Details
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover in github.com/getarcaneapp/arcane/backend
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/getarcaneapp/arcane/backend
Introduced in:
0Fixed in: 1.19.0Fix
go get github.com/getarcaneapp/arcane/backend@v1.19.0