CVE-2026-47852: Predictable cache directory location allows local ONNX model substitution in Spring AI
Published Aug 26, 2026
·Updated
A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9
Affected Software
3 affected components
Spring Spring AI=2.0.0
Spring Spring AI>=1.1.0<=1.1.8
Spring Spring AI>=1.0.0<=1.0.9
Event History
Aug 26, 2026
CVE Published
via MITRE·11:28 PM
Data Sourced
via MITRE·11:28 PM
DescriptionSeverityWeakness
Aug 27, 2026
Data Sourced
via NVD·01:17 AM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring AI releases should be reviewed for exposure?
Review Spring AI 2.0.0, Spring AI 1.1.0 through 1.1.8, and Spring AI 1.0.0 through 1.0.9.
2
What access does an attacker need to exploit this issue?
The attacker needs local access on a multi-user host and must be able to pre-create the deterministic cache path and place a malicious ONNX model file there.