Intel

AIKIDO-2026-10927

spring-ai-client-chat is vulnerable to Path Traversal

Path TraversalCVE-2026-41863 Published 2 days ago

60

Medium Risk

This Affects:

JAVAspring-ai-client-chat
1.1.0 - 1.1.6
Fixed in 1.1.7
Are you affected? Scan for Free

TL;DR

Affected versions of Spring AI are vulnerable to a path traversal issue in the Anthropic Skills API integration. LLM-influenced filenames were used without proper sanitization in Path.resolve before writing files, potentially allowing attackers to create or overwrite files outside the intended directory.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-ai-client-chat is vulnerable to Path Traversal in versions 1.1.0 - 1.1.6.

How to fix this

Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.