{"id":"CVE-2026-41863","aliases":["GHSA-cc4m-mp48-x7qg"],"url":"https://o3.security/vulnerability/CVE-2026-41863","summary":"LLM-influenced filename used unsanitized in Path.resolve before file write in Spring AI support for Anthropic Skills API","details":"Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the intended target directory, including restricted directories.\n\nAffected versions:\nSpring AI: 1.1.0 through 1.1.x","published":"2026-05-25T05:45:37.690Z","modified":"2026-08-12T03:51:48.605262109Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00398,"percentile":0.3304,"asOf":"2026-08-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.springframework.ai:spring-ai-anthropic","fixedVersion":"1.1.7"}],"fix":null,"references":[{"type":"WEB","url":"https://spring.io/security/cve-2026-41863"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41863.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41863"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:48.605262109Z"}}