Medium severity6.5NVD Advisory· Published Aug 21, 2026· Updated Sep 16, 2026
CVE-2026-59318
CVE-2026-59318
Description
In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched. Under certain conditions, a tool that was not made available to the current request could be invoked, potentially leading to privilege escalation. Affected versions: Spring AI: 2.0.0 Spring AI: 1.1.0 through 1.1.8 Spring AI: 1.0.0 through 1.0.9
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- spring.io/security/cve-2026-59318nvdVendor Advisory
News mentions
2- 91 Spring Vulnerabilities Impact 209,000+ Software Components Across Open-Source EcosystemCyber Security News · Aug 25, 2026
- 91 Vulnerabilities Patched in Spring Application FrameworkSecurityWeek · Aug 24, 2026