spring-ai-transformers is vulnerable to Uncontrolled Search Path Element
75
High Risk
spring-ai-transformers stores ONNX models in a deterministic cache path. A local attacker on a multi-user host can pre-create that path and plant a malicious model file. Later loads then execute or use the substituted model. The patch uses a cache location that cannot be predictably pre-created by another local user.
You are affected if you are using a version that falls within the vulnerable range and Transformers ONNX models are loaded from the default cache directory on a multi-user host.
spring-ai-transformers is vulnerable to Uncontrolled Search Path Element in versions 1.0.0 - 2.0.0.
Upgrade the org.springframework.ai:spring-ai-transformers library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant