spring-ai-model-chat-memory-repository-redis is vulnerable to Improper Neutralization of Special Elements in Data Query Logic
43
Medium Risk
spring-ai-model-chat-memory-repository-redis findByMetadata() builds RediSearch queries without RediSearchUtil.escape(), unlike other methods in the same class. A tag value such as x} | * can break out of the clause and match all indexed chat messages. That exposes conversation memory across tenants. The patch escapes metadata values before building the query.
You are affected if you are using a version that falls within the vulnerable range and user-controlled values are passed to RedisChatMemoryRepository.findByMetadata() on a tag-typed field.
spring-ai-model-chat-memory-repository-redis is vulnerable to Improper Neutralization of Special Elements in Data Query Logic in versions 2.0.0 - 2.0.0.
Upgrade the org.springframework.ai:spring-ai-model-chat-memory-repository-redis library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant