## https://sploitus.com/exploit?id=6694239F-3F74-59CD-A5FA-51EF6A6B2D27
# CVE-2026-60093 β camel-azure-storage-datalake `downloadToFile` path traversal
Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:
| Runtime | Directory | Stack |
|---------|-----------|-------|
| **Camel Spring Boot** | [`camel-spring-boot/`](camel-spring-boot/) | Spring Boot 3.5.13 + camel-azure-storage-datalake **4.18.2** |
| **Camel Quarkus** | [`camel-quarkus/`](camel-quarkus/) | Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel **4.20.0**) |
Both are **affected** versions (the issue is fixed in 4.14.9 / 4.18.4 / 4.22.0), and both demonstrate the identical
defect: the camel-azure-storage-datalake component can download an ADLS Gen2 file to the local filesystem through
its `downloadToFile` operation, writing into the directory named by the `fileDir` option.
`DataLakeFileOperations.downloadToFile` built the local target by joining `fileDir` with the remote path name
exactly as the Azure SDK reported it (`new File(fileDir, fileClientWrapper.getFileName())`) β with **no** lexical
normalization and **no** check that the resolved location stayed inside `fileDir`. The remote name is not
route-controlled: the consumer enumerates the filesystem (`DataLakeConsumer.createBatchExchangesFromPath`) and
downloads every entry. A path name containing `../` segments therefore resolves **outside** `fileDir` (CWE-22, path
traversal β arbitrary file write).
> **Note on the test harness.** The Azure **Data Lake Gen2** API is not implemented by any available local emulator
> β Azurite returns HTTP 400 for Gen2 `listPaths` and file operations. These reproducers therefore drive the exact
> vulnerable code (`DataLakeFileOperations.downloadToFile` β `new File(fileDir, fileClientWrapper.getFileName())`)
> **directly**, supplying a Data Lake file client wrapper whose `getFileName()` returns the remote name β exactly
> as the consumer supplies the name it read from `PathItem.getName()`. The sibling component
> `camel-azure-storage-blob` shares the same fix ([CVE-2026-66906](https://camel.apache.org/security/CVE-2026-66906.html))
> and there the identical defect is reproduced end-to-end against a live Azurite emulator.
```bash
cd camel-spring-boot # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down
```
Expected output on an affected build (both variants):
```
2) Download of a file named '../../../../../../tmp/pwned-60093.txt':
resolved local target: /app/downloads/../../../../../../tmp/pwned-60093.txt
File written OUTSIDE it, at /tmp/pwned-60093.txt: true
content: PWNED via path traversal β CVE-2026-60093
>>> PROVEN: DataLakeFileOperations.downloadToFile built the local target as new File(fileDir, fileName) ... : true
```
## Vulnerability Summary
| Property | Value |
|----------|-------|
| **Component** | `camel-azure-storage-datalake` (Spring Boot: `camel-azure-storage-datalake-starter`; Quarkus: `camel-quarkus-azure-storage-datalake`) |
| **CWE** | CWE-22 (Improper Limitation of a Pathname to a Restricted Directory β Path Traversal) |
| **Attack vector** | A Gen2 file whose path name contains `../` segments, downloaded by the consumer with `fileDir` set |
| **Impact** | Arbitrary file write outside the configured `fileDir` directory |
| **Affected Versions** | From 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0 |
| **Fixed Versions** | 4.14.9, 4.18.4, 4.22.0 |
| **JIRA** | [CAMEL-23942](https://issues.apache.org/jira/browse/CAMEL-23942) |
| **Credit** | n0mi1k; Hiep Nguyen |
Advisory: https://camel.apache.org/security/CVE-2026-60093.html
## The fix
The consumer now resolves and constrains the download target to the configured `fileDir` directory (via
`AzureFileNameHelper.resolveWithinDirectory`), rejecting path names that would escape it β the same fix that covers
`camel-azure-storage-blob` ([CVE-2026-66906](https://camel.apache.org/security/CVE-2026-66906.html)).
## Disclaimer
This repository is published for educational and defensive purposes: to help Apache Camel users understand the
vulnerability, verify whether they are affected, and confirm that upgrading resolves it. The written file is a
benign marker under `/tmp`. Do not use this material against systems you do not own or operate.