CVE-2026-59318

⚪ Do wiadomości

Niewłaściwe ograniczenie wywołań narzędzi w Spring AI może prowadzić do eskalacji uprawnień.

CVSS
6.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9

privilege-escalation Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2026-08-21 12:16:30 UTC
Ostatnia modyfikacja (NVD)2026-08-22 04:17:51 UTC
Referencje