CVE-2026-59318

medium

Description

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9

References

https://www.securityweek.com/91-vulnerabilities-patched-in-spring-application-framework/

https://spring.io/security/cve-2026-59318

Details

Source: Mitre, NVD

Published: 2026-08-21

Updated: 2026-08-22

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00168