Skip to content
VMwareCVE-2026-59294

VMware Spring AI: path traversal

Medium5.9CVE-2026-59294 · Published Aug 27, 2026 · updated Aug 31, 2026

ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.9 and earlier

VMware advisory

Affected versions

PackageAffectedFixed in
Spring AI
Product
<= 2.0.0No fix yet
>= 1.1.0, <= 1.1.8No fix yet
<= 1.0.9No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More VMware advisories

All VMware
Advisory
VMware Spring AMQP: resource leak
Medium6.5Aug 27
VMware Spring Integration: race condition
Medium4.2Aug 27
VMware Spring Integration: improper input validation
Medium6.3Aug 27
VMware Spring Integration: race condition
High8.2Aug 27
VMware Spring Integration: unsafe deserialization
High8.0Aug 27
VMware Spring Integration: link following
Medium6.8Aug 27

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.