CVE-2026-47852: A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Summary
A local attacker (someone with access to the same computer) on a shared machine can create a predictable storage folder path ahead of time and place a malicious ONNX model file (a machine learning model format) there, potentially compromising Spring AI applications. This vulnerability affects Spring AI versions 1.0.0 through 1.1.8 and version 2.0.0.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
network
low
none
none
August 26, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-47852
First tracked: August 27, 2026 at 02:07 AM
Classified by LLM (prompt v3) · confidence: 85%