cbcvebase.
CVE-2026-59318
published 2026-08-21

CVE-2026-59318: In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is…

PriorityP335medium6.5CVSS 3.1
AVNACHPRLUIRSCCHILAN
EPSS
0.17%
6.4th percentile
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9

Affected

3 ranges
VendorProductVersion rangeFixed in
springspring_ai
springspring_ai1.0.0 – 1.0.9
springspring_ai1.1.0 – 1.1.8
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.