spring-ai-client-chat is vulnerable to Path Traversal
60
Medium Risk
Affected versions of Spring AI are vulnerable to a path traversal issue in the Anthropic Skills API integration. LLM-influenced filenames were used without proper sanitization in Path.resolve before writing files, potentially allowing attackers to create or overwrite files outside the intended directory.
You are affected if using a vulnerable version.
spring-ai-client-chat is vulnerable to Path Traversal in versions 1.1.0 - 1.1.6.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant