CVE-2026-47852CWE-377

CVE-2026-47852

High · published August 27, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
10.2
In the wild
Unconfirmed
What it is

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.

Spring AI 2.0.0

Spring AI 1.1.0 - 1.1.8

Spring AI 1.0.0 - 1.0.9

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00202 · 10.2th percentile
Weakness
CWE-377 · Insecure Temporary File
Published
2026-08-27T05:17Z
Affected products (3)
ProductVersionsFixed in
vmware/spring_ai≥ 1.0.0, < 1.0.101.0.10
vmware/spring_ai≥ 1.1.0, < 1.1.91.1.9
vmware/spring_ai≥ 2.0.0, < 2.0.0.12.0.0.1
References (1)
EPSS history
Timeline
  • 28 AUG 06:43Z
    EPSS moved — → 0%
    epss
  • 26 AUG 23:28Z
    Predictable cache directory location allows local ONNX model substitution in Spring AI
    cvelistv5