LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 6.5epss 0.4%
probabilidade de exploração
0.4%top 66% das CVEs
exploração observada
nãonenhuma fonte reporta
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.
Affected versions:
Spring AI: 1.1.0 through 1.1.x
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Produtos afetados
Spring · Spring AIReferências
https://spring.io/security/cve-2026-41863