Junglewise Threat Intelligence

CVE-2026-59328: VMware Spring Tools for Eclipse Script Execution in Starter Wizard

CVE-2026-59328 · Severity: medium · CVSS 4.2 · Published 2026-07-30

Vendors: VMware.

Executive brief

Spring Tools for Eclipse is a development environment used by software engineers to build Spring Boot applications. A security flaw in the 'New Spring Starter Project' wizard allows a malicious or compromised project template source to execute scripts within the developer's tool. While this cannot take over the entire computer, it could be used to show fake login screens or track when a developer is using the tool.

Technical details

Spring Tools for Eclipse (versions 5.2.0 and earlier) utilizes an embedded SWT Browser with JavaScript enabled to render tooltips within the Spring Boot starter wizard. If a developer connects the wizard to an untrusted or compromised Initializr endpoint, an attacker can provide malicious metadata. When the developer hovers over a dependency checkbox, the embedded browser executes the attacker's JavaScript. The impact is restricted to the IDE's UI context, enabling UI spoofing and outbound network beaconing, but does not extend to full remote code execution on the host system.

Affected products

  • VMware Spring Tools for Eclipse 5.2.0 and earlier

Timeline

  • 2026-07-30: advisory: Advisory published by VMware and NVD

References