Junglewise Threat Intelligence

CVE-2026-78254: Apache Ant path traversal in FTP and SCP tasks

CVE-2026-78254 · Severity: high · CVSS 7.4 · Published 2026-09-07

Vendors: Apache.

Executive brief

Apache Ant is a build automation tool used to compile and package software. The FTP and SCP file download tasks can be tricked by a malicious server into writing files outside their intended directory, allowing an attacker to overwrite arbitrary files with the permissions of the user running Ant. This could lead to system compromise or data loss.

Technical details

This is a path traversal vulnerability in Apache Ant's ftp and scp tasks that download files from remote servers. The vulnerable code fails to properly validate or sanitize file paths provided by the server, allowing relative paths (e.g., "../") to escape the designated target directory. An attacker controlling the server (or intercepting traffic via man-in-the-middle attack) can provide crafted relative paths to write files to arbitrary locations. For scp and ftps, the attacker must pass server identity checks; for plain ftp without ftps, a network-positioned attacker can act as a man-in-the-middle. The fix in Ant 1.10.18 prevents writing outside the destination directory by default, with an option to restore the old behavior if needed for legacy build files.

Affected products

  • Apache Ant prior to 1.10.18

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Ant 1.10.18 released with fix

References