SQL injection in Spring AI - CVE-2026-41705
Published: May 11, 2026
Spring AI
Pivotal
Description
The vulnerability allows a remote attacker to disclose sensitive information and delete data.
The vulnerability exists due to improper neutralization of special elements in a query in MilvusVectorStore#doDelete(List) when processing unsanitized document IDs in filter expressions. A remote attacker can supply crafted document IDs to disclose sensitive information and delete data.