PT-2026-79377 · Vmware · Spring Ai
CVE-2026-59318
·
Published
2026-08-21
·
Updated
2026-08-28
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spring AI version 2.0.0
Spring AI versions 1.1.0 through 1.1.8
Spring AI versions 1.0.0 through 1.0.9
Description
In the tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced during tool call dispatch. This allows a tool not provided to the current request to be invoked under certain conditions, which could lead to privilege escalation. This issue is related to the
DefaultToolCallingManager global resolver fallback allowing unadvertised tool dispatch via prompt injection, a technique where specially crafted inputs are used to manipulate the model's output.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Ai