THREAT OPS › Threat News › CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
<p>Posted by Stefan Bodewig on Sep 06</p>Severity: moderate <br /> <br /> Affected versions:<br /> <br /> - Apache Ant (org.apache.ant:ant) 1.2 before 1.10.18<br /> <br /> Description:<br /> <br /> The ftp and scp tasks of Apache Ant can download files from a remote<br /> server. A malicious server can provide relative paths that allow it to<br /> write outside of the dedicated target directory fo
Indicators of compromise
- CVE-2026-78254cve
Original source: https://seclists.org/oss-sec/2026/q3/660