CyberRota Analysis
AI-GeneratedA local attacker on a multi-user host can exploit a vulnerability in Spring AI versions 1.0.0 to 2.0.0 by pre-creating a deterministic cache path to inject a malicious ONNX model file. This could lead to unauthorized execution of arbitrary code, potentially compromising the integrity and confidentiality of the affected system. Organizations using these versions of Spring AI, especially in multi-user environments, should prioritize patching to mitigate this high-severity risk.
Original NVD Description
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Related CVEs
Other vulnerabilities affecting the same vendor(s)