PT-2026-108893 · Apache · Apache Camel Karavan

·

CVE-2026-103412

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Camel Karavan versions 3.18.0 through 4.22.0
Description An authenticated user with any role can exploit a path traversal issue where a project file name provided via the project file API is used without proper validation when writing the project to a working copy for a Git commit. By including ../ sequences in the file name, an attacker can write file content outside the intended project directory to any location writable by the process. This can lead to the overwriting of application configuration or files on the application classpath, potentially resulting in remote code execution within the container.
Recommendations Upgrade to version 4.22.1.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103412

Affected Products

Apache Camel Karavan