Executive brief
Spring AI's resource caching mechanism downloads and stores files locally based on URIs provided by applications. A flaw in filename construction allows attackers to write files to arbitrary locations on disk by crafting URIs with path traversal sequences (like "../"), potentially overwriting sensitive files or executing arbitrary code if combined with other attack vectors.
Technical details
The vulnerability exists in ResourceCacheService.getCacheName(), which constructs on-disk filenames by concatenating a resource parent folder path with a URI fragment without sanitizing path separators or ".." sequences. This unsanitized filename is then passed to the File constructor before writing downloaded content, enabling path traversal attacks. An attacker can craft a malicious URI with fragments like "../../sensitive/file.txt" to write arbitrary content outside the intended cache directory. The vulnerability requires network access to trigger the download, but no authentication is required. Patched versions should sanitize URI fragments by removing or escaping path traversal sequences.
Affected products
- VMware Spring AI 1.0.9 and earlier, 1.1.0–1.1.8, 2.0.0
Timeline
- 2026-08-27: disclosed