Arbitrary Script Execution in Spring Tools for Eclipse by Spring
CVE-2026-59328
4.2MEDIUM
What is CVE-2026-59328?
The Spring Tools for Eclipse contains a vulnerability where the Spring Boot starter wizard renders dependency tooltips within a native embedded browser that has JavaScript enabled. If developers utilize untrusted or compromised Initializr endpoints for the Spring Boot starter wizard, they may inadvertently trigger arbitrary script execution upon hovering over a dependency checkbox. While the immediate impact entails in-IDE UI spoofing and potential outbound network beaconing, it does not culminate in full code execution, posing a risk primarily within the Integrated Development Environment.
Affected Version(s)
Spring Tools for Eclipse 0 <= 5.2.0
