Executive brief
Spring Integration, a framework for building enterprise messaging applications, contains a symlink attack vulnerability in its Zip/UnZip transformer component. A local attacker with unprivileged access to the same system can pre-create a malicious symlink to redirect compressed file output to arbitrary directories, potentially enabling unauthorized file creation, overwriting, or data exfiltration within the application's filesystem.
Technical details
The vulnerability is a symlink attack (TOCTOU/insecure temporary file) in Spring Integration's Zip/UnZip transformer. An unprivileged local attacker can pre-create /tmp/ziptransformer as a symlink pointing to a directory of their choosing before the application starts processing archive operations. The transformer does not follow secure temporary file handling practices, failing to check for or safely handle symlinks. This allows the attacker to redirect all transformer output to an arbitrary location, potentially overwriting files or accessing sensitive data. The issue affects Spring Integration versions 6.4.0–6.4.12, 6.5.0–6.5.10, and 7.0.0–7.0.5 (7.1.0 also affected). A patch is expected from Spring Security.
Affected products
- Spring Spring Integration 6.4.0–6.4.12, 6.5.0–6.5.10, 7.0.0–7.0.5, 7.1.0
Timeline
- 2026-08-27: disclosed