Intel

AIKIDO-2026-10800

spring-ai-client-chat is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-41713 Published May 13, 2026

80

High Risk

This Affects:

JAVAspring-ai-client-chat
1.0.0 - 1.0.6
Fixed in 1.0.7
1.1.0 - 1.1.5
Fixed in 1.1.6
Are you affected? Scan for Free

TL;DR

Applications using the affected advisor may allow a malicious user to inject crafted input into conversation memory that is later interpreted by the model in an unintended manner. This can enable manipulation of model behavior across subsequent conversation turns when user-controlled input is stored and reused.

Who does this affect?

You are affected if using a vulnerable version and your applications uses VectorStoreChatMemoryAdvisor.

Background info

spring-ai-client-chat is vulnerable to Improper Input Validation in versions 1.1.0 - 1.1.5 and 1.0.0 - 1.0.6.

How to fix this

Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.