File Path Vulnerability in Spring AI by VMware
CVE-2026-59294
5.9MEDIUM
What is CVE-2026-59294?
A security flaw in VMware's Spring AI allows for unsafe file path construction within the ResourceCacheService. The method getCacheName() directly appends URI fragments to create on-disk filenames without sanitizing input. This could lead to unauthorized file access or overwriting sensitive files on the server when writing downloaded data. This vulnerability affects multiple versions of Spring AI, from 1.0.0 through 2.0.0, emphasizing the importance of proper input validation and secure file handling.
Affected Version(s)
Spring AI 2.0.0
Spring AI 1.1.0 <= 1.1.8
Spring AI 0 <= 1.0.9
