Executive brief
Apache InLong is a data integration platform used to collect and move data between systems. A path traversal vulnerability in the Agent component allows attackers to read arbitrary files from the host filesystem, potentially exposing sensitive configuration files, credentials, or other protected data.
Technical details
A relative path traversal vulnerability exists in Apache InLong's Agent component due to insufficient validation of file source paths. An attacker can craft malicious input using path traversal sequences (e.g., ../) to escape the intended directory and read arbitrary files from the Agent host filesystem. The vulnerability affects versions 2.0.0 through 2.3.x; exploitation requires network access to the Agent. The vulnerability has been patched in version 2.4.0, and users are advised to upgrade or apply the fix from https://github.com/apache/inlong/pull/12146.
Affected products
- Apache InLong 2.0.0 to 2.3.x
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Fix available in version 2.4.0