SB20260828161 - Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring AI
Published: August 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary queries.
The vulnerability exists due to improper neutralization of special elements in spring ai vector store metadata filtering in Elasticsearch, OpenSearch, and GemFire vector stores when processing metadata filter input. A remote attacker can supply special characters in crafted metadata filters to execute arbitrary queries.
Remediation
Install update from vendor's website.