Executive brief
Apache Ant is a build automation tool used to compile and package software. The FTP and SCP file download tasks can be tricked by a malicious server into writing files outside their intended directory, allowing an attacker to overwrite arbitrary files with the permissions of the user running Ant. This could lead to system compromise or data loss.
Technical details
This is a path traversal vulnerability in Apache Ant's ftp and scp tasks that download files from remote servers. The vulnerable code fails to properly validate or sanitize file paths provided by the server, allowing relative paths (e.g., "../") to escape the designated target directory. An attacker controlling the server (or intercepting traffic via man-in-the-middle attack) can provide crafted relative paths to write files to arbitrary locations. For scp and ftps, the attacker must pass server identity checks; for plain ftp without ftps, a network-positioned attacker can act as a man-in-the-middle. The fix in Ant 1.10.18 prevents writing outside the destination directory by default, with an option to restore the old behavior if needed for legacy build files.
Affected products
- Apache Ant prior to 1.10.18
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Ant 1.10.18 released with fix