Feed/CVE-2026-41863
CVE-2026-41863MEDIUMCVSS 6.5

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk

Published May 26, 2026·Updated Jun 30, 2026

NVD Description

Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories. Affected versions: Spring AI: 1.1.0 through 1.1.7

Affected Packages (1)

org.springframework.ai:spring-ai-anthropicMAVEN
From 1.1.0
Fixed in 1.1.7

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free