CVE-2026-22738 identifies a critical SpEL injection vulnerability within Spring AI's SimpleVectorStore, enabling arbitrary code execution when user-supplied input is utilized as a filter expression key. This affects Spring AI versions from 1.0.0 before 1.0.5 and from 1.1.0 before 1.1.4. Rated 9.8 CRITICAL, the flaw has a network attack vector, low attack complexity, and requires no privileges or user interaction, leading to a complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code available, the vulnerability is garnering community attention due to its potential for unauthenticated Remote Code Execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.4CPE matchmatch criteria | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.