THREATOPS
THREAT OPSThreat News › CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write

CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write

medoss_secPublished 2026-09-06

<p>Posted by Stefan Bodewig on Sep 06</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Ant (org.apache.ant:ant) 1.2 before 1.10.18<br /> <br /> Description:<br /> <br /> The ftp and scp tasks of Apache Ant can download files from a remote<br /> server. A malicious server can provide relative paths that allow it to<br /> write outside of the dedicated target directory fo

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/660