spring-ai-client-chat is vulnerable to Improper Input Validation
80
High Risk
Applications using the affected advisor may allow a malicious user to inject crafted input into conversation memory that is later interpreted by the model in an unintended manner. This can enable manipulation of model behavior across subsequent conversation turns when user-controlled input is stored and reused.
You are affected if using a vulnerable version and your applications uses VectorStoreChatMemoryAdvisor.
spring-ai-client-chat is vulnerable to Improper Input Validation in versions 1.1.0 - 1.1.5 and 1.0.0 - 1.0.6.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant