Spring AI Local Path Traversal in ONNX Model Loading (1.01.0.9,1.1.01.1.8,2.0.0)
CVE-2026-47852 Published on August 26, 2026
Predictable cache directory location allows local ONNX model substitution in Spring AI
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9
Vulnerability Analysis
CVE-2026-47852 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
Insecure Temporary File
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Products Associated with CVE-2026-47852
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring AI:- Version 2.0.0 is affected.
- Version 1.1.0, <= 1.1.8 is affected.
- Version 1.0.0, <= 1.0.9 is affected.