Spring AI's MilvusVectorStore Vulnerable to Injection Attacks
CVE-2026-41705
8.6HIGH
What is CVE-2026-41705?
The MilvusVectorStore implementation in Spring AI is susceptible to filter-expression injection due to unsanitized document IDs. This vulnerability allows an attacker to potentially manipulate data queries by exploiting the injection point, leading to unauthorized access or data leakage. It is crucial for users of Spring AI versions 1.0.0 to 1.0.x and 1.1.0 to 1.1.x to upgrade to at least versions 1.0.7 and 1.1.6 respectively to mitigate this risk.
Affected Version(s)
Spring AI 1.0.0 < 1.0.7
Spring AI 1.1.0 < 1.1.6
