spring-ai-client-chat is vulnerable to SQL Injection
88
High Risk
Affected versions of Spring AI are vulnerable to SQL injection. In Spring AI's CosmosDBVectorStore allows attackers to execute arbitrary SQL queries via crafted document IDs. Only applications that use CosmosDBVectorStore and pass user-supplied input as document ids are affected.
You are affected if using a vulnerable version and your applications uses CosmosDBVectorStore.
spring-ai-client-chat is vulnerable to SQL Injection in versions 1.1.0 - 1.1.4 and 1.0.0 - 1.0.5.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant