CyberRota Analysis
AI-GeneratedThe vulnerability in Spring AI's tool calling support allows unauthorized tool invocation due to insufficient enforcement of the per-request tool list, which could lead to privilege escalation. Affected versions include 2.0.0 and 1.0.0 through 1.1.8. Organizations utilizing Spring AI should prioritize patching this issue to mitigate potential security risks.
Original NVD Description
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9
Related CVEs
Other vulnerabilities affecting the same vendor(s)