Arbitrary Script Execution in Spring Tools for Eclipse by Spring
CVE-2026-59328

4.2MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
30 July 2026

What is CVE-2026-59328?

The Spring Tools for Eclipse contains a vulnerability where the Spring Boot starter wizard renders dependency tooltips within a native embedded browser that has JavaScript enabled. If developers utilize untrusted or compromised Initializr endpoints for the Spring Boot starter wizard, they may inadvertently trigger arbitrary script execution upon hovering over a dependency checkbox. While the immediate impact entails in-IDE UI spoofing and potential outbound network beaconing, it does not culminate in full code execution, posing a risk primarily within the Integrated Development Environment.

Affected Version(s)

Spring Tools for Eclipse 0 <= 5.2.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.