Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreIn Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId.
Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.
Spring AI:
Users of affected versions should upgrade to the corresponding fixed version.
| Affected version(s) | Fix version | Availability |
|---|---|---|
| 1.0.x | 1.0.6 | OSS |
| 1.1.x | 1.1.5 | OSS |
No further mitigation steps are necessary.
The issue was reported responsibly by
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy