CVE-2026-57898: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Eclipse Foundation Eclipse BaSyx - Java Server SDK
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. A remote attacker could upload thumbnail content using an absolute or traversal-style filename, then trigger thumbnail retrieval so that the uploaded bytes were written to the attacker-chosen path on the server filesystem. This could allow writing files anywhere the Java process has permission to write and may lead to remote code execution. The default InMemory backend is not affected by this specific path because it normalizes and restricts file paths to its temporary directory. The issue is fixed in Eclipse BaSyx Java Server SDK 2.0.0-milestone-13.
AI Analysis
Technical Summary
The Eclipse BaSyx Java Server SDK's AAS thumbnail upload functionality accepts a client-controlled filename parameter that is used as a key in the MongoDB GridFS repository without normalization or path restriction. This allows an attacker to upload files using absolute or traversal-style paths. When the thumbnail is retrieved, the server writes the file to the specified path on the filesystem. This improper limitation of pathname (CWE-22) can lead to arbitrary file write and potentially remote code execution. The issue affects versions from 2.0.0-milestone-05 up to and including 2.0.0-milestone-12 and is fixed in 2.0.0-milestone-13.
Potential Impact
An unauthenticated remote attacker can write arbitrary files anywhere on the server filesystem where the Java process has write permissions. This can lead to remote code execution and full compromise of the affected system. The default InMemory backend is not affected. The vulnerability has a CVSS 3.1 score of 9.0 (critical).
Mitigation Recommendations
The vulnerability is fixed in Eclipse BaSyx Java Server SDK version 2.0.0-milestone-13. Users should upgrade to this version or later to remediate the issue. No official patch or temporary fix is documented beyond upgrading. Until upgrade, avoid using the MongoDB backend or restrict access to the vulnerable API if possible.
CVE-2026-57898: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Eclipse Foundation Eclipse BaSyx - Java Server SDK
Description
In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled fileName request parameter and passed it through repository file handling as both a repository key and, during thumbnail retrieval, a local filesystem path. With the MongoDB file repository, the supplied filename was treated as an opaque GridFS key and was not normalized or restricted as a filesystem path. A remote attacker could upload thumbnail content using an absolute or traversal-style filename, then trigger thumbnail retrieval so that the uploaded bytes were written to the attacker-chosen path on the server filesystem. This could allow writing files anywhere the Java process has permission to write and may lead to remote code execution. The default InMemory backend is not affected by this specific path because it normalizes and restricts file paths to its temporary directory. The issue is fixed in Eclipse BaSyx Java Server SDK 2.0.0-milestone-13.
CVSS v3.1
Score 9.0critical
Affected software
pkg:github/Eclipse BaSyx - Java Server SDKRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Eclipse BaSyx Java Server SDK's AAS thumbnail upload functionality accepts a client-controlled filename parameter that is used as a key in the MongoDB GridFS repository without normalization or path restriction. This allows an attacker to upload files using absolute or traversal-style paths. When the thumbnail is retrieved, the server writes the file to the specified path on the filesystem. This improper limitation of pathname (CWE-22) can lead to arbitrary file write and potentially remote code execution. The issue affects versions from 2.0.0-milestone-05 up to and including 2.0.0-milestone-12 and is fixed in 2.0.0-milestone-13.
Potential Impact
An unauthenticated remote attacker can write arbitrary files anywhere on the server filesystem where the Java process has write permissions. This can lead to remote code execution and full compromise of the affected system. The default InMemory backend is not affected. The vulnerability has a CVSS 3.1 score of 9.0 (critical).
Mitigation Recommendations
The vulnerability is fixed in Eclipse BaSyx Java Server SDK version 2.0.0-milestone-13. Users should upgrade to this version or later to remediate the issue. No official patch or temporary fix is documented beyond upgrading. Until upgrade, avoid using the MongoDB backend or restrict access to the vulnerable API if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-07-08T14:11:22.756Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a55f44d68715ace431bbf37
Added to database: 07/14/2026, 08:33:17 UTC
Last enriched: 07/14/2026, 08:47:36 UTC
Last updated: 08/27/2026, 18:10:08 UTC
Views: 154
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.