Vmware · Spring Ai · CVE-2026-41705
**Name of the Vulnerable Software and Affected Versions**
Spring AI versions 1.0.0 through 1.0.6
Spring AI versions 1.1.0 through 1.1.5
**Description**
The `doDelete(List)` function in the MilvusVectorStore implementation is susceptible to filter-expression injection. This occurs because document IDs are not properly sanitized, which could allow an attacker to destroy data.
**Recommendations**
Upgrade Spring AI versions 1.0.0 through 1.0.6 to 1.0.7 or greater.
Upgrade Spring AI versions 1.1.0 through 1.1.5 to 1.1.6 or greater.