Improper Neutralization of Special Elements in Output Used by a Downstream Component in Spring AI - CVE-2026-47835
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary queries.
The vulnerability exists due to improper neutralization of special elements in spring ai vector store metadata filtering in Elasticsearch, OpenSearch, and GemFire vector stores when processing metadata filter input. A remote attacker can supply special characters in crafted metadata filters to execute arbitrary queries.