CVE Explorer
CVE-2026-59328
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution.
Aff
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Spring Tools for Eclipse","vendor":"Spring","versions":[{"lessThanOrEqual":"5.2.0","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/adp/0/problemTypes/0/descriptions/0
{"description":"CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://spring.io/security/cve-2026-59328"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8aaf379adec0536574637c1443fc982880c391cdd852c4285e75a785cf701636 · sha256:fbe83e5494d4933d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.