Intel

AIKIDO-2026-571052

spring-integration-file is vulnerable to Path Traversal

Path TraversalCVE-2026-40987 Published Today

80

High Risk

This Affects:

javaspring-integration-file
0.0.1 - 5.5.20
Fixed in 5.5.21
6.0.0 - 6.3.14
Fixed in 6.3.15
6.4.0 - 6.4.11
Fixed in 6.4.12
6.5.0 - 6.5.8
Fixed in 6.5.8.1
7.0.0 - 7.0.4
Fixed in 7.0.4.1
Are you affected? Scan for Free

TL;DR

Spring Integration contains a path traversal vulnerability in its remote file synchronization components. A malicious or compromised FTP, SFTP, or SMB server can provide crafted filenames that are written to the client filesystem without proper path canonicalization. This may allow files to be created or overwritten outside the configured local directory, potentially leading to unauthorized file modification, data corruption, or execution of attacker-controlled content.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-integration-file is vulnerable to Path Traversal in versions 0.0.1 - 5.5.20, 6.0.0 - 6.3.14, 6.4.0 - 6.4.11, 6.5.0 - 6.5.8 and 7.0.0 - 7.0.4.

How to fix this

Upgrade the org.springframework.integration:spring-integration-file library to a patch version.