Intel

AIKIDO-2026-10801

spring-ai-client-chat is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-41705 Published May 13, 2026

80

High Risk

This Affects:

JAVAspring-ai-client-chat
1.0.0 - 1.0.6
Fixed in 1.0.7
1.1.0 - 1.1.5
Fixed in 1.1.6
Are you affected? Scan for Free

TL;DR

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs.

Who does this affect?

You are affected if using a vulnerable version and your applications uses VectorStoreChatMemoryAdvisor.

Background info

spring-ai-client-chat is vulnerable to Improper Input Validation in versions 1.1.0 - 1.1.5 and 1.0.0 - 1.0.6.

How to fix this

Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.