← Security advisories
Apache Camel security advisory

CVE-2025-66169

Cypher injection vulnerability in Camel-Neo4j component

Description

Camel neo4j component is vulnerable to Cypher injection: attackers can construct specific query statements to execute unintended operations in the Neo4j database.

Mitigation

Users are recommended to upgrade to version 4.10.8 for 4.10.x LTS and 4.14.3 for 4.14.x LTS and 4.17.0.

Credit

This issue was discovered and reported by Ya0H4cker.

Notes

The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-22719 refers to the commit that resolved the issue, and have more details.

References