spring-ai-transformers is vulnerable to Path Traversal
59
Medium Risk
spring-ai-transformers ResourceCacheService.getCacheName() appends a URI fragment to the cache filename without stripping separators or ... A crafted fragment can write downloaded bytes outside the cache directory. Tenant configuration or an admin UI that supplies the model URI is enough to trigger this. The patch sanitizes the fragment before building the cache path.
You are affected if you are using a version that falls within the vulnerable range and model or tokenizer URIs from a less-trusted source are passed to TransformersEmbeddingModel.
spring-ai-transformers is vulnerable to Path Traversal in versions 0.0.1 - 2.0.0.
Upgrade the org.springframework.ai:spring-ai-transformers library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant