Arbitrary Argument Injection Affecting org.apache.camel:camel-docling package, versions [,4.18.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.78% (76th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHECAMEL-17892569
  • published8 Jul 2026
  • disclosed6 Jul 2026
  • creditAndrea Cosentino

Introduced: 6 Jul 2026

CVE-2026-40047  (opens in a new tab)
CWE-88  (opens in a new tab)

How to fix?

Upgrade org.apache.camel:camel-docling to version 4.18.3 or higher.

Overview

Affected versions of this package are vulnerable to Arbitrary Argument Injection via the DoclingProducer custom CLI argument handling in camel-docling. An attacker can pass untrusted values through the CamelDoclingCustomArguments header to make the producer append unintended docling flags or path arguments when it launches the external docling process. This lets a route that forwards attacker-controlled message content into those headers alter the subprocess invocation, including supplying traversal-prone path values that escape the intended directory and changing how document conversion runs for the user.

CVSS Base Scores

version 4.0
version 3.1