{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-47852", "assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d", "state": "PUBLISHED", "assignerShortName": "vmware", "dateReserved": "2026-05-20T10:00:53.147Z", "datePublished": "2026-08-26T23:28:42.767Z", "dateUpdated": "2026-08-27T15:13:55.925Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d", "shortName": "vmware", "dateUpdated": "2026-08-26T23:28:42.767Z" }, "title": "Predictable cache directory location allows local ONNX model substitution in Spring AI", "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-377 Insecure Temporary File", "type": "CWE" } ] } ], "impacts": [ { "descriptions": [ { "lang": "en", "value": "A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file." } ] } ], "affected": [ { "vendor": "Spring", "product": "Spring AI", "versions": [ { "status": "affected", "version": "2.0.0", "versionType": "custom" }, { "status": "affected", "version": "1.1.0", "lessThanOrEqual": "1.1.8", "versionType": "custom" }, { "status": "affected", "version": "1.0.0", "lessThanOrEqual": "1.0.9", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.\nSpring AI 2.0.0\nSpring AI 1.1.0 - 1.1.8\nSpring AI 1.0.0 - 1.0.9", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.
Spring AI 2.0.0
Spring AI 1.1.0 - 1.1.8
Spring AI 1.0.0 - 1.0.9