CVE-2026-47852
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Summary
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring AI | 2.0.0 | affected |
| Spring | Spring AI | 1.1.0 <= 1.1.8 | affected |
| Spring | Spring AI | 1.0.0 <= 1.0.9 | affected |
Weaknesses
- CWE-377 Insecure Temporary File
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.