spring-ai-client-chat is vulnerable to Insecure Temporary File
61
Medium Risk
Affected versions of Spring AI may create insecure temporary files. Having access to a shared environment can expose the ONNX model used by the application. Only applications that use TransformersEmbeddingModel and have the cache enabled, using the default location, are affected.
You are affected if using a vulnerable version and your applications uses TransformersEmbeddingModel and have the cache enabled, using the default location.
spring-ai-client-chat is vulnerable to Insecure Temporary File in versions 1.1.0 - 1.1.4 and 1.0.0 - 1.0.5.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant