As part of the Spotlight protocol, the initial request returns a path associated with the sharename targeted by the RPC request. Samba returns the real server-side share path at this point, as well as returning the absolute server-side path of results in search queries by clients.
This CVE is public now - https://www.samba.org/samba/security/CVE-2023-34968.html.
Created samba tracking bugs for this issue: Affects: fedora-all [bug 2224250]