Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.
Affected versions:
Spring AI: 1.1.0 through 1.1.x
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-41863 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-05-25 07:16
Updated : 2026-07-23 17:10
NVD link : CVE-2026-41863
Mitre link : CVE-2026-41863
CVE.ORG link : CVE-2026-41863
JSON object : View
Products Affected
vmware
- spring_ai
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
