
Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-66906) in camel-azure-storage-blob, demonstrating arbitrary file write via blob name traversal, with affected and fixed version details.
downloadBlobToFile path traversalRunnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:
Both are affected versions (the issue is fixed in 4.14.9 / 4.18.4 / 4.22.0), and both demonstrate the identical
defect: the camel-azure-storage-blob consumer downloads container blobs to the local filesystem into the directory
named by the fileDir option, building the local target as new File(fileDir, client.getBlobName()) — the remote
blob name exactly as the Azure SDK reported it, with no normalization and no check that the resolved
location stays inside fileDir. The blob name is not route-controlled: the consumer lists the container
(BlobConsumer.createBatchExchangesFromContainer) and downloads every blob. A blob whose name contains ../
segments is therefore written outside fileDir (CWE-22, path traversal → arbitrary file write).
Each subdirectory is self-contained (its own Dockerfile, docker-compose.yml bringing up an
Azurite emulator, and README). In short, for either:
cd camel-spring-boot # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down
Expected output on an affected build (both variants):
Files inside the intended download directory /app/downloads:
- report.txt
File written OUTSIDE it, at /tmp/pwned-66906.txt: true
content: PWNED via path traversal — CVE-2026-66906
>>> PROVEN: the blob name's ../ segments escaped the configured fileDir directory ... : true
Advisory: https://camel.apache.org/security/CVE-2026-66906.html
The consumer now resolves and constrains the download target to the configured fileDir directory (via
AzureFileNameHelper.resolveWithinDirectory), rejecting blob names that would escape it. The same fix covers the
sibling components camel-azure-storage-datalake (CVE-2026-60093).
This repository is published for educational and defensive purposes: to help Apache Camel users understand the
vulnerability, verify whether they are affected, and confirm that upgrading resolves it. The written file is a
benign marker under /tmp. Do not use this material against systems you do not own or operate.
| Runtime | Directory | Stack |
|---|
| Camel Spring Boot | camel-spring-boot/ | Spring Boot 3.5.13 + camel-azure-storage-blob 4.18.2 |
| Camel Quarkus | camel-quarkus/ | Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0) |
| Property | Value |
|---|
| Component | camel-azure-storage-blob (Spring Boot: camel-azure-storage-blob-starter; Quarkus: camel-quarkus-azure-storage-blob) |
| CWE | CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal) |
| Attack vector | A container blob whose name contains ../ segments, downloaded by the consumer with fileDir set |
| Impact | Arbitrary file write outside the configured fileDir directory |
| Affected Versions | From 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0 |
| Fixed Versions | 4.14.9, 4.18.4, 4.22.0 |
| JIRA | CAMEL-23942 |
| Credit | n0mi1k; Hiep Nguyen |