Apache Camel security advisory
CVE-2025-66169
Cypher injection vulnerability in Camel-Neo4j component
Description
Camel neo4j component is vulnerable to Cypher injection: attackers can construct specific query statements to execute unintended operations in the Neo4j database.
Mitigation
Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.
Credit
This issue was discovered and reported by Ya0H4cker.
Notes
The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-22719 refers to the commit that resolved the issue, and have more details.