CVE-2026-22729: high-severity vulnerability in VMware Spring AI
CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling attackers to inject arbitrary JSONPath logic and access unauthorized documents.
This vulnerability affects applications using vector stores that extend AbstractFilterExpressionConverter for multi-tenant isolation, role-based access control, or document filtering based on metadata.
The vulnerability occurs when user-supplied values in filter expressions are not escaped before being inserted into JSONPath queries. Special characters like ", ||, and && are passed through unescaped, allowing injection of arbitrary JSONPath logic that can alter the intended query semantics.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
VMware · Spring AIRelated CVEs — VMware Spring AI
In the same product, most dangerous first.
CVE-2026-22730HIGHCVE-2026-22730: SQL Injection in Spring AI MariaDBFilterExpressionConverterEPSS 0.5%CVE-2026-41712HIGHChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakageEPSS 0.4%CVE-2026-40966MEDIUMVectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltrationEPSS 0.4%CVE-2026-41713HIGHPrompt Injection via Memory Poisoning in PromptChatMemoryAdvisorEPSS 0.4%