File Path Vulnerability in Spring AI by VMware
CVE-2026-59294

5.9MEDIUM

Key Information:

Vendor

Spring

Status
Vendor
CVE Published:
27 August 2026

What is CVE-2026-59294?

A security flaw in VMware's Spring AI allows for unsafe file path construction within the ResourceCacheService. The method getCacheName() directly appends URI fragments to create on-disk filenames without sanitizing input. This could lead to unauthorized file access or overwriting sensitive files on the server when writing downloaded data. This vulnerability affects multiple versions of Spring AI, from 1.0.0 through 2.0.0, emphasizing the importance of proper input validation and secure file handling.

Affected Version(s)

Spring AI 2.0.0

Spring AI 1.1.0 <= 1.1.8

Spring AI 0 <= 1.0.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.