CVE-2026-47852

Updated on 27 Aug 2026

Severity

7.0 High severity

Details

CVSS score
7.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Overview

About vulnerability

A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.

Details

Affected product:
Spring
Affected packages:
spring-ai-starter-model-stability-ai @ 1.1.8 (+327 more)