PT-2026-25940 · Vmware · Spring Ai
Published
2026-03-17
·
Updated
2026-03-18
·
CVE-2026-22730
CVSS v3.1
8.8
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands.
The vulnerability exists due to missing input sanitization.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spring Ai