
A PoC/exploit has been discovered for vulnerability CVE-2026-40047 PT ID: PT-2026-55881 Vendor: Apache Software Foundation Product: Apache Camel Description: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-docling component invokes the external "docling" command-line tool by assembling an argument list in DoclingProducer and executing it through java.lang.ProcessBuilder. Custom CLI arguments supplied through the "CamelDoclingCustomArguments" exchange header (a List<String>) were appended to that argument list with insufficient validation: the original implementation relied on a denylist of disallowed flags and only rejected path values that contained a literal "../" sequence. As a result, a Camel route that forwards externally-influenced data into the "CamelDoclingCustomArguments" header (or into the path-bearing headers used to build the invocation) could cause the producer to pass unrecognized or unintended "docling" CLI flags to the subprocess, and could supply path-like argument values that resolved outside the intended directory through traversal sequences not caught by the literal "../" check. Because Camel itself builds the "docling" invocation from these values, the component is responsible for constraining them, and the weak validation allowed CLI-argument injection and directory traversal in the arguments passed to the external tool. The invocation uses the list-based form of ProcessBuilder, so a shell does not interpret the argument values; OS command injection through shell metacharacters was not possible, and the metacharacter rejection added by the fix is defense-in-depth. This issue affects Apache Camel: from 4.15.0 before 4.18.3. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55881 • https://github.com/oscerd/CVE-2026-40047 #dbugs_vuln
Post summary
A PoC and exploit for CVE-2026-40047 was published, demonstrating CLI argument injection in Apache Camel’s Docling component; no evidence of current exploitation or patch has been provided.
