Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverter
Vulnerability Description
A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
VMware Spring AI 安全漏洞
Vulnerability Description
VMware Spring AI是美国威睿(VMware)公司的一个在Spring生态中集成人工智能与大语言模型能力的开发框架。 VMware Spring AI存在安全漏洞,该漏洞源于MariaDBFilterExpressionConverter缺少输入清理,可能导致攻击者绕过基于元数据的访问控制并执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A