spring-ai-client-chat is vulnerable to Code Injection
86
High Risk
Affected versions of Spring AI are vulnerable to Code Injection. Various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages. In several cases, keys and values are not properly escaped, leading to the ability to alter the query. Only applications that use VectorStore implementations and pass user-supplied input as a filterExpression are affected.
You are affected if using a vulnerable version and your applications uses VectorStore implementations.
spring-ai-client-chat is vulnerable to Code Injection in versions 1.1.0 - 1.1.4 and 1.0.0 - 1.0.5.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant