Executive brief
Spring Integration is a framework used by Java applications to connect with external systems like file servers. A vulnerability in its file support allows a malicious or compromised FTP, SFTP, or SMB server to write files to any location on the client's computer. This could allow an attacker to overwrite critical system files or plant malicious software, potentially leading to a full system compromise.
Technical details
A path traversal vulnerability (CWE-22) exists in the Spring Integration File Support module. When a client application connects to a malicious or compromised FTP, SFTP, or SMB server, the server can provide file paths containing traversal sequences (e.g., ../) that the client does not properly neutralize. This allows the server to write files with attacker-controlled content outside of the intended local directory on the client's filesystem. The vulnerability affects the 'spring-integration-file' artifact across multiple major versions. Users should upgrade to version 7.0.5 or later to mitigate this issue.
Affected products
- VMware Spring Integration 7.0.0 to 7.0.4, 6.5.0 to 6.5.8, 6.4.0 to 6.4.11, 6.3.0 to 6.3.14, 5.5.0 to 5.5.20
Timeline
- 2026-06-11: disclosed
- 2026-06-11: advisory
- 2026-07-24: patched: GitHub advisory updated with patched version 7.0.5