A major security vulnerability has been discovered in Apache Jackrabbit, a popular open source content repository used in enterprise content management systems and web applications.

This vulnerability could allow unauthorized users (attackers) to achieve arbitrary code execution (RCE) on servers running vulnerable versions.
The vulnerability, tracked as JCR-5135, is classified as a 'Deserialization of Untrusted Data' issue. It is located in the way certain components of Apache Jackrabbit handle Java Naming and Directory Interface (JNDI) lookups. Specifically, if a deployment is configured to accept JNDI URIs for Java Content Repository (JCR) lookups from untrusted or publicly accessible sources, an attacker could exploit this route.
See also: Malicious npm packages mimic Flashbots & steal wallet keys
Where can the exploitation of the Apache Jackrabbit vulnerability lead?
By submitting a specially crafted, malicious JNDI reference, an attacker can trick the application into processing it. This action triggers the deserialization of untrusted data from a source controlled by the attacker. This, in turn, can lead to the execution of arbitrary commands on the underlying server with the privileges of the application.
A successful exploit could allow an attacker to install malicious software, steal sensitive data , or take complete control of the affected system.
Security researcher James John reported the content repository security flaw.
Which versions are affected?
The vulnerability is widespread, affecting multiple versions of two of the project's core components. All users running the following versions are at risk and should check their systems immediately:
- Apache Jackrabbit Core (org.apache.jackrabbit:jackrabbit-core): Versions 1.0.0 to 2.22.1
- Apache Jackrabbit JCR Commons (org.apache.jackrabbit:jackrabbit-jcr-commons): Versions 1.0.0 to 2.22.1
To address this significant risk, the Apache Jackrabbit project team has released a patch. Administrators are strongly encouraged to upgrade all affected deployments to version 2.22.2 or later.
See also: Critical vulnerability in Argo CD API exposes repository credentials

The primary fix includes disabling JCR lookups via JNDI by default (which closes the attack path for most users).
Those who need this specific functionality must enable it via a system property. Anyone who re-enables this feature should perform a careful security review of its use, ensuring that unvalidated, user-supplied data cannot affect the JNDI URI.
Implementing the update is the most effective way to mitigate the threat.
The JCR-5135 vulnerability in Apache Jackrabbit is not just another “technical bug”; it’s a wake-up call for the way we think about security in the open source ecosystem. Jackrabbit is at the heart of dozens of CMSs, enterprise applications, and web projects, meaning the chain of risk is not limited to individual developers but extends to entire organizations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The most worrying aspect is that this is a classic case of deserialization of untrusted data. Despite repeated warnings from the security community for years, we continue to see vulnerabilities that allow an attacker to “load” malicious objects and gain complete control. This shows that the industry has not yet adopted a “secure by design” culture in its libraries.
See also: A2: New AI tool for discovering & validating Android vulnerabilities

The need for immediate upgrades is self-evident, but the real lesson lies elsewhere: in dependency management. Many organizations don’t even have a record of which frameworks and which versions they’re running, leaving them exposed for weeks or even months. In a world where RCE can mean ransomware, customer data leaks , or sabotage of critical infrastructure, a late response isn’t just careless—it’s a risk with unpredictable consequences.
Finally, the Jackrabbit case confirms the importance of responsible disclosure and active maintenance in open-source projects. Without ongoing oversight, even the most popular tools can become “weak links” on a global scale. The community is called upon not to rest on the idea that open source automatically means security; it requires investment, collaboration, and vigilance.
