CVE-2026-59294EPSS p27.6%

CVE-2026-59294CVE-2026-59294

vmware / spring_ai

Description

ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.9 and earlier

Scoring

CVSS 5.9 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
EPSS0.36% probability of exploitation · percentile 27.6% · 2026-10-05T12:00:23Z
Last modified2026-08-31
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.