CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Published Aug 20, 2026
·Updated
Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12146 .
Affected Software
1 affected component
Apache Inlong>=2.0.0<2.4.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache InLongto a version that resolves this vulnerability.Fixed in 2.4.0
Event History
Aug 20, 2026
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionWeakness
Frequently Asked Questions
1
Which deployments are affected?
Apache InLong versions from 2.0.0 up to, but not including, 2.4.0 are affected. The issue is in the Agent component and can expose files on the Agent host filesystem.
2
What should be done to remediate the issue?
Upgrade Apache InLong to version 2.4.0. If an upgrade is not immediately possible, cherry-pick the fix referenced as pull request 12146.