Spring Tools for Eclipse vulnerability

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

Published 30 Jul 2026Updated 8 Sep 20261 sources
CVSS 8.0

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.