Arbitrary File Write Vulnerability in Spring Integration by Pivotal Software
CVE-2026-47862
5.4MEDIUM
What is CVE-2026-47862?
An arbitrary file write vulnerability exists in Spring Integration, where an attacker can manipulate the 'file_name' header on a message processed by a ZipTransformer. This flaw allows for the creation of a .zip archive that can be written to any file path outside of the predetermined workDirectory. This could lead to potential exposure of sensitive files or system compromise. It is critical for users of the affected versions to apply necessary mitigations to secure their application.
Affected Version(s)
Spring Integration 7.1.0
Spring Integration 7.0.0 <= 7.0.5
Spring Integration 6.5.0 <= 6.5.10
