CVE-2026-41713
EUVD-2026-2944912.05.2026, 11:16
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_ai | 1.0.0 ≤ 𝑥 < 1.0.7 |
| vmware | spring_ai | 1.1.0 ≤ 𝑥 < 1.1.6 |
𝑥
= Vulnerable software versions