CVE-2026-41863

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories. Affected versions: Spring AI: 1.1.0 through 1.1.x
References
Link Resource
https://spring.io/security/cve-2026-41863 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-25 07:16

Updated : 2026-07-23 17:10


NVD link : CVE-2026-41863

Mitre link : CVE-2026-41863

CVE.ORG link : CVE-2026-41863


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')