HugeGraph is a full-stack graph system covering graph database, graph computing, and graph AI. It provides complete graph data processing capabilities from storage and real-time querying to offline analysis, and supports both Gremlin and Cypher query languages.
Apache HugeGraph suffers from a remote code execution vulnerability caused by a bypass of its SecurityManager-based Gremlin execution sandbox. HugeGraph executes submitted Gremlin as Groovy and relies on a custom HugeSecurityManager to block operating-system access, but that manager only denies calls whose current thread name identifies them as Gremlin threads. By defining a class whose finalize() method runs an operating-system command and forcing garbage collection, the command executes on the JVM Finalizer thread, where the check does not apply, and the sandbox is bypassed. Because authentication is disabled in the default configuration, a remote attacker can reach the Gremlin endpoint and execute arbitrary OS commands with root privileges.