Intel

AIKIDO-2026-10673

spring-ai-client-chat is vulnerable to Insecure Temporary File

Insecure Temporary FileCVE-2026-40979 Published Apr 30, 2026

61

Medium Risk

This Affects:

JAVAspring-ai-client-chat
1.0.0 - 1.0.5
Fixed in 1.0.6
1.1.0 - 1.1.4
Fixed in 1.1.5
Are you affected? Scan for Free

TL;DR

Affected versions of Spring AI may create insecure temporary files. Having access to a shared environment can expose the ONNX model used by the application. Only applications that use TransformersEmbeddingModel and have the cache enabled, using the default location, are affected.

Who does this affect?

You are affected if using a vulnerable version and your applications uses TransformersEmbeddingModel and have the cache enabled, using the default location.

Background info

spring-ai-client-chat is vulnerable to Insecure Temporary File in versions 1.1.0 - 1.1.4 and 1.0.0 - 1.0.5.

How to fix this

Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.