SQL injection in Spring AI - CVE-2026-22730
Published: April 28, 2026
Spring AI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary SQL commands.
The vulnerability exists due to missing input sanitization in MariaDBFilterExpressionConverter when processing user-supplied filter expressions. A remote user can send a specially crafted input to execute arbitrary SQL commands.
The issue can be used to bypass metadata-based access controls.