
CVE-2026-41863 Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious us… https://www.cve.org/CVERecord?id=CVE-2026-41863
Post summary
The tweet announces CVE-2026-41863, noting that Spring AI’s use of unsanitized filenames from Anthropic’s Skills API could lead to unsafe file writes.
