{"id":"CVE-2026-103412","summary":"Apache Camel Karavan: project file name path traversal when committing a project to Git","details":"Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan.\n\n\n\nA project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container.\n\n\n\nThis issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1.\n\n\n\nUsers are recommended to upgrade to version 4.22.1, which fixes the issue.","modified":"2026-10-11T07:05:33.656044955Z","published":"2026-10-09T12:53:13.660Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103412.json","cna_assigner":"apache","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/10/09/16"},{"type":"ADVISORY","url":"https://camel.apache.org/security/CVE-2026-103412.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103412.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103412"},{"type":"FIX","url":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/camel-karavan","events":[{"introduced":"782487168237f0abf3aa151dfd1afda627aafbca"},{"fixed":"d6f7b0da5302ac99198f854b3b110aee21c2ed5e"},{"fixed":"5e4252494817af0cd2697216bd02f361037fedcf"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"3.18.0"},{"fixed":"4.22.1"}]}}],"versions":["4.18.1","4.14.2","4.10.2","4.10.0","4.8.0","4.7.0","4.6.0","4.5.0","4.4.0","4.3.1","4.3.0","4.1.0","4.0.0","3.21.0","3.20.1","3.20.0","3.18.5","3.18.4","3.18.3","3.18.2","3.18.1","3.18.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103412.json","vanir_signatures":[{"digest":{"line_hashes":["330761266203589351727833100004852767757","85671382782480764409334278756122726198","127085199341914167322109671512713002034","138449012603719153994717494794329776246","194377357289672481633781720660478707841","129063349500559368416136648184131169515","198793028745925141979462615872309620027","183283031381172848513819097318718148516","107238162866060248910441167467273491959"],"threshold":0.9},"id":"CVE-2026-103412-01daee56","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/service/CodeService.java"},"deprecated":false},{"target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/api/ProjectFileResource.java","function":"copy"},"deprecated":false,"digest":{"function_hash":"29574473326443191829877820457635613771","length":670},"id":"CVE-2026-103412-0c76bf0e","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf"},{"deprecated":false,"digest":{"function_hash":"234715883554999902013643399189826842358","length":256},"id":"CVE-2026-103412-171f1a5e","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/service/CodeService.java","function":"addFile"}},{"id":"CVE-2026-103412-4491bd45","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/api/ProjectFileResource.java","function":"create"},"deprecated":false,"digest":{"function_hash":"248688780648142183437037994372114330656","length":501}},{"target":{"function":"rename","file":"karavan-app/src/main/java/org/apache/camel/karavan/api/ProjectFileResource.java"},"deprecated":false,"digest":{"length":934,"function_hash":"231848328124538230811056712250845031878"},"id":"CVE-2026-103412-4be34090","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf"},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["230232007953736879781669731175216811315","290554901694788783574685830000097989949","20419253384393999222140604683255701313","248896571718173204896339795001712799242","68096567708733942637053033514764711520","78718661912825325663076548928154776212","260670576542091291595169954639189431915","339089252593989858164441221347973360467","47988382740176450592696906345437100814","55836407408354939202904649441159524491","59608926599389462247807693589295024346","176021793322555976078909804524629530639","195473263299303554106866143161729162665"]},"id":"CVE-2026-103412-53ea5bc7","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/service/GitService.java"}},{"id":"CVE-2026-103412-75917fbd","signature_type":"Function","signature_version":"v1","source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/api/ProjectFileResource.java","function":"update"},"deprecated":false,"digest":{"function_hash":"108439766338134824416462960728658805201","length":185}},{"source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/service/GitService.java","function":"writeProjectToFolder"},"deprecated":false,"digest":{"length":528,"function_hash":"10878583598341210145852430441597704898"},"id":"CVE-2026-103412-9e7f3ed9","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","target":{"file":"karavan-app/src/main/java/org/apache/camel/karavan/api/ProjectFileResource.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["258268396448721565022581670745238593562","321204069578726304966831924386520571170","219861190285052906100210049002826387433","285501635243652145234227188174288833964","105446546672160371564891602066329996227","209678854797136745794300321013912658039","220745842659805743674115560818272917987","281106589820964375299703318055240521605","82041618988386868074335315571121003947","324937673766552328363332946467139008312","268298470765614214759287548084279329215","86015823462802619342069617886321333028","86191944226521453083998799222363834701","134858104833129392173677658180601172022","29823852453467537995346423572693178630","180723053205799935496590827685133418814","246887907567958680409463268336921296443","79227440151110654232900301775938473117","70474680267072087620943973139912280978","316280642874564926389847810705971107038","208866235979593079669258046821126775067","57655452230277831957539385146657643760","191870308086906105780710925926383688582","235044287703126575120579132231617551664","246852913161079834290974016786115791296","295535476118074722852802175914336168622","196244883391451749466591295854077577438"]},"id":"CVE-2026-103412-e96eadb0","signature_type":"Line","signature_version":"v1"}],"vanir_signatures_modified":"2026-10-11T07:05:33Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}