Executive brief
Spring AI is a framework used to integrate artificial intelligence capabilities into Java applications. A security flaw in its integration with Anthropic's AI services allows the AI to influence the names of files written to the server's disk. A malicious user could exploit this to save files in unauthorized locations, potentially overwriting critical system files or planting malicious scripts.
Technical details
A path traversal vulnerability (CWE-22) exists in the Spring AI Anthropic module. The vulnerability stems from the improper sanitization of filenames generated or influenced by a Large Language Model (LLM) when using Anthropic's Skills API. These unsanitized strings are passed directly to Path.resolve() before being written to the filesystem. An attacker with network access and low privileges can provide input that causes the LLM to generate path traversal sequences (e.g., ../), allowing the attacker to write files to arbitrary locations on the host system. This issue is resolved in Spring AI version 1.1.7.
Affected products
- Spring Spring AI Anthropic 1.1.0 to 1.1.6
Timeline
- 2026-05-25: disclosed: NVD publication date
- 2026-05-26: advisory: GitHub Advisory published
- 2026-06-30: patched: Advisory updated with patch information