CVE-2026-59294

ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.9 and earlier
References
Link Resource
https://spring.io/security/cve-2026-59294 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-27 20:17

Updated : 2026-08-31 23:24


NVD link : CVE-2026-59294

Mitre link : CVE-2026-59294

CVE.ORG link : CVE-2026-59294


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')