CVE-2026-40047 is an argument-injection and directory-traversal vulnerability in Apache Camel's camel-docling component. DoclingProducer constructs an argument list for the external docling command-line tool and executes it with java.lang.ProcessBuilder. Before the CAMEL-23212 fix, custom arguments supplied in the CamelDoclingCustomArguments exchange header and path-bearing header values were insufficiently validated. The implementation used a denylist for flags and rejected only paths containing a literal ../ sequence, allowing unrecognized or unintended docling options and traversal variants that could resolve outside the intended directory. Apache Camel versions from 4.15.0 before 4.18.3 are affected. Because ProcessBuilder receives a list of arguments rather than invoking a shell, shell-metacharacter OS command injection is not possible through this issue.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a functional proof-of-concept and local reproducer for CVE-2026-40047, an Apache Camel camel-docling argument injection/path traversal issue affecting versions 4.15.0 through 4.18.2. The repo contains two main parts: a Python exploit client (CVE-2026-40047.py) and a Java/Spring Boot vulnerable demo application backed by Apache Camel and a stubbed docling CLI. The Python script is the main exploit driver. It performs target reachability checks, sends a benign request to /exploit/normal, and sends exploit requests to /exploit/attack with attacker-controlled query parameters flag and value. It determines vulnerability by comparing responses and checking whether injected arguments appear in the returned output or invocation log. It also supports custom injection values such as --artifacts-path /tmp/pwned. The Java application is a deliberate reproducer. Application.java starts Spring Boot; DoclingRoute.java defines a Camel route from direct:convert to the camel-docling endpoint docling:convert?operation=CONVERT_TO_MARKDOWN&contentInBody=true; ExploitController.java exposes /exploit/normal and /exploit/attack. The attack endpoint places user-supplied values into the CamelDoclingCustomArguments header, which is the vulnerable input path. The controller also sets CamelDoclingInputFilePath and returns the subprocess invocation log so the injection is observable. The Bash script docling-stub.sh is not malicious payload code; it is an instrumentation stub that replaces the real docling binary in Docker. It logs received arguments to /tmp/docling-invocations.log and writes a markdown output file, allowing the exploit to prove that arbitrary CLI flags reached the subprocess. Dockerfile and docker-compose.yml provide a self-contained lab environment exposing the app on port 8080. pom.xml pins camel-docling to 4.18.2, an affected version, confirming the target product and vulnerable dependency. Overall, the repository's purpose is to demonstrate and validate remote web-triggered CLI argument injection into an external process via Apache Camel headers, rather than to deliver post-exploitation code such as a shell.
This repository is a working reproducer for CVE-2026-40047 in Apache Camel's camel-docling component. It is not a generic exploit framework module; it is a standalone Spring Boot + Apache Camel demo application packaged for Docker. The exploit capability is CLI argument injection into the external 'docling' subprocess by supplying attacker-controlled values in the CamelDoclingCustomArguments header, plus injection of path-like values that bypass weak traversal checks. The code explicitly notes this is not OS shell command injection because Camel uses ProcessBuilder in list form. Repository structure: Application.java is the Spring Boot entry point; DoclingRoute.java defines a Camel route from direct:convert to docling:convert?operation=CONVERT_TO_MARKDOWN&contentInBody=true; ExploitController.java exposes HTTP endpoints under /exploit that prepare input, set Camel headers, invoke the route, and return the observed results; docling-stub.sh is a fake docling binary that logs argv to /tmp/docling-invocations.log and writes a markdown output file so the route completes successfully; Dockerfile and docker-compose.yml package and expose the app on port 8080. application.properties sets the server port and Camel app name. Main exploit flow: a GET request to /exploit/attack causes the controller to create /tmp/input.txt, set CamelDoclingInputFilePath and CamelDoclingCustomArguments headers, and invoke the internal Camel route. On vulnerable camel-docling 4.18.2 (pinned in pom.xml), the custom arguments are appended to the docling command line and reach the stub subprocess. The response includes both the route result and the invocation log, making the injection observable. A benign /exploit/normal endpoint is also provided for comparison. Overall, this is an operational PoC/reproducer demonstrating exploitation conditions and observable impact for a publicly disclosed vulnerability in Apache Camel camel-docling.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical argument-injection and path-traversal vulnerability in Apache Camel's camel-docling component. Insufficient validation of externally influenced CamelDoclingCustomArguments and path-bearing headers can permit unintended docling CLI flags and paths resolving outside the intended directory. Shell command injection via metacharacters is not possible because ProcessBuilder uses an argument list rather than a shell.
An argument-injection and path-traversal vulnerability in Apache Camel's camel-docling (DoclingProducer) component. Externally influenced custom arguments could bypass denylist-based validation, allowing unintended docling flags or normalized paths outside the intended directory. Shell command injection via metacharacters was not possible because ProcessBuilder used list-based argument execution rather than a shell.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.