Apache Gravitino URL Path Injection Vulnerability Allowing Unintended API Endpoint Access

Vulnerability

A URL path injection vulnerability has been identified in Apache Gravitino versions 1.0.0 prior to 1.2.1. This issue arises from unencoded user-supplied identifiers, which can be exploited to traverse paths and access unintended API endpoints via the MCP REST client.

Impact

Exploitation of this vulnerability allows for path traversal to unintended API endpoints, potentially leading to unauthorized access or manipulation of resources.

Remediation

Users are advised to upgrade to Apache Gravitino version 1.2.1 or later, which addresses this vulnerability.

Added: Jul 13, 2026, 11:54 AM
Updated: Jul 13, 2026, 11:54 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.