Executive brief
When developers use Spring Tools to run Spring Boot applications with 'live information mode' enabled, the running application becomes vulnerable to remote attacks. An attacker on the same network could potentially execute unauthorized code on the developer's machine or the server running the application. This could lead to a full system compromise, data theft, or unauthorized access to development environments.
Technical details
A remote code execution (RCE) vulnerability exists in Spring Tools when Spring Boot applications are launched with 'live information mode' active. This mode enables Java Management Extensions (JMX) in a manner that allows for unauthenticated remote interaction. An attacker with adjacent network access can leverage the JMX interface to execute arbitrary code within the context of the running application. The vulnerability affects Spring Tools for Eclipse (5.2.0 and earlier) and Spring Tools for VSCode/Cursor/Theia (2.2.0 and earlier). Users should update to newer versions of these tools to mitigate the risk.
Affected products
- Spring Spring Tools for Eclipse 5.2.0 and earlier
- Spring Spring Tools for VSCode / Cursor / Theia 2.2.0 and earlier
Timeline
- 2026-07-30: advisory: Initial publication of the advisory.