CVE-2026-59318

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9
References
Link Resource
https://spring.io/security/cve-2026-59318 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*

History

16 Sep 2026, 14:01

Type Values Removed Values Added
First Time Vmware spring Ai
Vmware
References () https://spring.io/security/cve-2026-59318 - () https://spring.io/security/cve-2026-59318 - Vendor Advisory
CPE cpe:2.3:a:vmware:spring_ai:*:-:*:*:*:*:*:*

Information

Published : 2026-08-21 12:16

Updated : 2026-09-16 14:01


NVD link : CVE-2026-59318

Mitre link : CVE-2026-59318

CVE.ORG link : CVE-2026-59318


JSON object : View

Products Affected

vmware

  • spring_ai
CWE
CWE-863

Incorrect Authorization