ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.9 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-59294 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-27 20:17
Updated : 2026-08-31 23:24
NVD link : CVE-2026-59294
Mitre link : CVE-2026-59294
CVE.ORG link : CVE-2026-59294
JSON object : View
Products Affected
vmware
- spring_ai
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
