A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-41863

CVE-2026-41863: Spring AI Path Traversal Vulnerability

CVE-2026-41863 is a path traversal flaw in Spring AI's Anthropic Skills API that allows attackers to write files outside intended directories. This article covers technical details, affected versions, and mitigation.

Published: May 28, 2026

CVE-2026-41863 Overview

CVE-2026-41863 is a path traversal vulnerability [CWE-22] in Spring AI's integration with Anthropic's Skills API. The framework passed large language model (LLM) influenced filenames directly to Path.resolve without sanitization before writing files to disk. An authenticated attacker can craft input that causes the application to write files outside the intended target directory, including into restricted system directories. The flaw affects Spring AI versions 1.1.0 through 1.1.x.

Critical Impact

A malicious actor can manipulate LLM-controlled filenames to write arbitrary files outside the target directory, enabling overwrite of sensitive files and potential follow-on code execution.

Affected Products

  • Spring AI 1.1.0 through 1.1.x
  • Applications integrating Spring AI with Anthropic's Skills API
  • Java services using Spring AI file-handling components for LLM outputs

Discovery Timeline

  • 2026-05-25 - CVE-2026-41863 published to NVD
  • 2026-05-26 - Last updated in NVD database

Technical Details for CVE-2026-41863

Vulnerability Analysis

The vulnerability resides in Spring AI's handler for Anthropic's Skills API. Skills can produce files that the framework persists to disk on behalf of the calling application. The filename component of those outputs is influenced by the LLM and, by extension, by user input that reaches the model.

Spring AI passed these filenames directly to Path.resolve without normalization or validation. Path.resolve honors absolute paths and traversal sequences such as ../, so a filename containing path separators escapes the intended output directory. The result is a classic directory traversal weakness ([CWE-22]) reachable through indirect, model-mediated input.

Integrity is the primary impact. An attacker cannot directly read existing files through this flaw, but file overwrite in writable locations can corrupt application data, plant configuration files, or replace executable artifacts.

Root Cause

The root cause is missing input sanitization on filenames returned through the Skills API workflow. The code assumed model-influenced filenames were safe relative identifiers. It did not verify that the resolved path stayed within the configured target directory, nor did it reject absolute paths or .. segments.

Attack Vector

The attack vector is network-based and requires low privileges. An authenticated user submits a prompt or request that causes the Anthropic Skill to return a file whose name contains traversal sequences or an absolute path. Spring AI resolves and writes that file, placing attacker-controlled content at the chosen location. No user interaction beyond the initial request is required.

The vulnerability is described in prose only; refer to the Spring Security Advisory for CVE-2026-41863 for vendor-confirmed technical details.

Detection Methods for CVE-2026-41863

Indicators of Compromise

  • Files created outside the configured Spring AI working directory, particularly under system paths such as /etc, /var, or application binary locations.
  • Application log entries showing Path.resolve operations on filenames containing .., /, or \ characters.
  • Unexpected modifications to configuration files, startup scripts, or static web assets shortly after Anthropic Skills API calls.

Detection Strategies

  • Audit Spring AI dependency versions across build manifests and identify any deployment running 1.1.0 through 1.1.x.
  • Inspect application logs for file write operations triggered by Skills API responses and correlate target paths against the expected output directory.
  • Add filesystem integrity monitoring on directories that host Spring AI deployments and adjacent sensitive paths.

Monitoring Recommendations

  • Alert on process file writes where the destination path is outside an allow-listed output directory for the Spring AI service account.
  • Capture and review LLM prompt and response payloads for filename fields containing path separators or absolute path prefixes.
  • Track outbound traffic to the Anthropic API alongside subsequent filesystem activity to establish a baseline for anomaly detection.

How to Mitigate CVE-2026-41863

Immediate Actions Required

  • Upgrade Spring AI to a fixed release as identified in the Spring Security Advisory for CVE-2026-41863.
  • Restrict the operating system permissions of the service account running Spring AI so it cannot write outside its working directory.
  • Review recent Skills API activity for filenames containing .., forward slashes, backslashes, or drive letters.

Patch Information

Spring has published a security advisory for CVE-2026-41863. Consult the Spring Security Advisory for CVE-2026-41863 for the patched version range and upgrade guidance. Apply the fixed release in development, staging, and production environments and rebuild any container images that bundle Spring AI.

Workarounds

  • Wrap or override the Skills API file-writing component to validate that the resolved path is a child of the intended output directory before writing.
  • Sanitize filenames returned from the LLM by stripping path separators and rejecting absolute paths or .. sequences.
  • Run the Spring AI process in a sandbox or container with a read-only root filesystem and a single writable mount point for legitimate output.
bash
# Configuration example
# Verify Spring AI version in a Maven project before and after patching
mvn dependency:tree | grep spring-ai

# Run the service under a dedicated, least-privileged user with a restricted writable directory
useradd -r -s /usr/sbin/nologin springai
install -d -o springai -g springai -m 0750 /var/lib/springai/skills-output

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePath Traversal

  • Vendor/TechSpring Ai

  • SeverityMEDIUM

  • CVSS Score6.5

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityNone
  • CWE References
  • CWE-22
  • Technical References
  • Spring Security Advisory for CVE-2026-41863
  • Related CVEs
  • CVE-2026-22744: Spring AI Redis Store XSS Vulnerability

  • CVE-2026-22738: Spring AI SpEL Injection RCE Vulnerability

  • CVE-2026-22730: Spring AI MariaDB SQLi Vulnerability

  • CVE-2026-22729: Spring AI Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English