spring-ai-client-chat is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
80
High Risk
Affected versions of Spring AI use a default conversation identifier in the chat memory component, which can cause conversation data to be shared unintentionally between users. Applications that do not explicitly set a conversation ID may expose chat history or context across user sessions, leading to cross-user data leakage.
You are affected if using a vulnerable version and your applications uses VectorStoreChatMemoryAdvisor.
spring-ai-client-chat is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.1.0 - 1.1.5 and 1.0.0 - 1.0.6.
Upgrade the org.springframework.ai:spring-ai-client-chat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant