Overview
About vulnerability
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file.Details
- Affected product:
- Spring
- Affected packages:
- spring-ai-starter-model-stability-ai @ 1.1.8 (+327 more)