https://seclists.org/oss-sec/2026/q3/537: CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Published Aug 20, 2026
·Updated
Affected Software
1 affected component
Apache Inlong<2.4.0
Frequently Asked Questions
1
Which deployments are affected?
Apache InLong versions 2.0.0 through versions before 2.4.0 are affected. The vulnerable component is the Agent, and the impact is arbitrary file reading from the Agent host filesystem.
2
What should teams do to remediate the issue?
Upgrade Apache InLong to version 2.4.0. If upgrading is not immediately possible, cherry-pick the referenced fix in Apache InLong pull request 12146.