← Back

CVE-2026-41863

nvd nist
Published: May 25, 2026Modified: Jul 23, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: security@vmware.com (Secondary)

Description

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories. Affected versions: Spring AI: 1.1.0 through 1.1.x

Affected (1)

Products: Vmware: Spring Ai
1 product
Spring Ai
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.1.0 to 1.1.7

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.