Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreSpring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.
Spring AI:
Spring AI:
| Fix version | Availability |
|---|---|
| 1.1.7 | OSS |
No further mitigation steps are necessary.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy