spring-ai-model is vulnerable to Incorrect Authorization
65
Medium Risk
spring-ai-model DefaultToolCallingManager advertises a per-request tool list but can dispatch a tool that was not offered on that request. Prompt-injected tool names may therefore run with higher privilege than the request allowed. That is a tool-calling authorization bypass. The patch dispatches only tools advertised on the current request.
You are affected if you are using a version that falls within the vulnerable range and DefaultToolCallingManager can fall back to a global tool resolver.
spring-ai-model is vulnerable to Incorrect Authorization in versions 1.0.0 - 2.0.0.
Upgrade the org.springframework.ai:spring-ai-model library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant