CVE-2026-23944: Arcane Env Proxy Middleware Without Auth Validator

NewEnvProxyMiddlewareWithParam is invoked without an AuthValidator argument. The environment proxy middleware runs before route-level authentication and, when an environment ID is non-local, forwards the request to the remote agent with the manager-held agent access token attached. Without an AuthValidator, unauthenticated callers gain agent-level access to

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0Go
greprules fetch cve-2026-23944-arcane-env-proxy-middleware-without-auth-validator --engine opengrep

Description

NewEnvProxyMiddlewareWithParam is invoked without an AuthValidator argument. The environment proxy middleware runs before route-level authentication and, when an environment ID is non-local, forwards the request to the remote agent with the manager-held agent access token attached. Without an AuthValidator, unauthenticated callers gain agent-level access to