在 Spring AI 的工具调用支持中,每次请求的工具列表被宣传为对模型使用的边界限制,但在实际派发工具调用时并未得到完全强制执行。在特定条件下,可能调用未在当前请求中提供的工具,从而导致权限提升。 受影响版本: Spring AI: 2.0.0 Spring AI: 1.1.0 至 1.1.8 Spring AI: 1.0.0 至 1.0.9
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59279 | 7.5 HIGH | Unbounded persistent session allocation via repeated initialize requests |
| CVE-2026-59308 | 4.2 MEDIUM | Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation |
No comments yet