MEDIUM 6.1 Maven
Spring AI's ONNX model cache defaults to world-writable predictable /tmp directory
GHSA-r5hp-3cgj-j6xv · CVE-2026-40979
Published · Modified
Description
In Spring AI, having access to a shared environment can expose the ONNX model used by the application.
Affected versions:
Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5)
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes