WhisperX tag archive

#Spring AI

This page collects WhisperX intelligence signals tagged #Spring AI. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-05-09 07:31:50 · Mastodon:mastodon.social:#infosec

1. CVE-2026-41705: Spring AI MilvusVectorStore Flaw Enables Filter-Expression Injection via Unsanitized Document IDs

A high-severity vulnerability has been identified in Spring AI's MilvusVectorStore component, exposing applications to filter-expression injection attacks. Tracked as CVE-2026-41705 with a CVSS score of 8.6, the flaw resides in the doDelete(List) implementation, where unsanitized document IDs are passed directly into f...

The Lab · 2026-05-12 13:18:27 · Mastodon:mastodon.social:#infosec

2. Spring AI Chat Memory Component Exposed Users to Cross-Tenant Data Leak via Risky Default Setting

A high-severity vulnerability in Spring AI's chat memory component has been identified, carrying a CVSS score of 7.5. The flaw stems from a problematic default configuration that, when left unaddressed by developers, can expose conversation data between different users. This represents a classic case of secure-by-defau...