Description
Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier
Published: 2026-07-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted dependency list returned by an untrusted or compromised Initializr endpoint can cause the Eclipse Spring Tools for Eclipse wizard to render malicious JavaScript in its embedded SWT Browser. When a developer hovers over a dependency checkbox in the New Spring Starter Project wizard, the malicious script runs inside the IDE’s browser context. The attack is limited to user‑interface spoofing and outbound network beaconing; it does not grant full code execution or system compromise. The likely attack vector is reliance on an untrusted Initializr service that supplies unvalidated content to the wizard.

Affected Systems

All users of Spring Tools for Eclipse 5.2.0 and earlier are affected when they launch the New Spring Starter Project wizard and use a compromised Initializr endpoint. The vulnerability does not extend to newer releases such as 5.3.0 and later.

Risk and Exploitability

The CVSS score of 4.2 indicates a medium risk, and the EPSS score of less than 1 % shows a very low probability of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be within the IDE and to have the wizard open; the attacker can influence the user experience and cause the IDE to send network beaconing traffic.

Generated by OpenCVE AI on August 3, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Spring Tools for Eclipse to version 5.3.0 or later
  • Configure the IDE to use only trusted Initializr endpoints or restrict the wizard to internal services
  • If possible, disable JavaScript execution in the Eclipse SWT Browser to prevent script rendering

Generated by OpenCVE AI on August 3, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Tools For Eclipse
Weaknesses CWE-79
Vendors & Products Spring
Spring spring Tools For Eclipse
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Title Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Spring Spring Tools For Eclipse
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-07-30T13:45:05.145Z

Reserved: 2026-07-04T18:14:10.167Z

Link: CVE-2026-59328

cve-icon Vulnrichment

Updated: 2026-07-30T13:44:59.860Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-30T06:25:55.920

Modified: 2026-07-30T14:17:01.167

Link: CVE-2026-59328

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')