Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.
Spring AI:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 1.1.x | 1.1.7 | OSS |
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy