CVE-2026-22729Disclosure(vmware / spring_ai)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_ai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling attackers to inject arbitrary JSONPath logic and access unauthorized documents. This vulnerability affects applications using vector stores that extend AbstractFilterExpressionConverter for multi-tenant isolation, role-based access control, or document filtering based on metadata. The vulnerability occurs when user-supplied values in filter expressions are not escaped before being inserted into JSONPath queries. Special characters like ", ||, and && are passed through unescaped, allowing injection of arbitrary JSONPath logic that can alter the intended query semantics.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-917

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_ai

Threat summary

  • Patch or workaround signal is available
  • 16 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 14 signals
  • Disclosure: 11 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 8 mentions (2026-03-18); latest day: 1
  • 16 total mentions across 6 days

Affected systems

Vendors
Products
spring_ai

Deep dive

Activity timeline16 mentions / 6d
02468Mentions · 2026-03-17: 1Mentions · 2026-03-18: 8Mentions · 2026-03-19: 4Mentions · 2026-03-23: 1Mentions · 2026-04-10: 1Mentions · 2026-09-22: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 8Technical Details · 2026-03-19: 3Technical Details · 2026-03-23: 1Technical Details · 2026-04-10: 103-1703-1803-1903-2304-1009-22
Signal classification3 categories
Disclosure
1168.8%
General
318.8%
Patch
212.5%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-171
Disclosure1
2026-03-188
Disclosure6General1Patch1
2026-03-194
Disclosure3General1
2026-03-231
Patch1
2026-04-101
Disclosure1
2026-09-221
General1
Full discourse16 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-22729: JSONPath Injection in Spring AI’s PgVectorStore https://blog.securelayer7.net/cve-2026-22729-jsonpath-injection-spring-ai-pgvectorstore/

    Post summary

    The text announces a newly identified JSONPath injection vulnerability in Spring AI’s PgVectorStore and directs readers to a blog post for further details.

    07035162.5K
    153.3K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Two critical flaws in Spring AI (CVE-2026-22729 & CVE-2026-22730) allow attackers to bypass access controls via JSONPath and SQL injection. Update now. #SpringAI #CVE #CyberSecurity #InfoSec #SQLInjection #JavaSecurity #Vulnerability #AppSec #TechNews https://securityonline.info/critical-spring-ai-vulnerabilities-sql-jsonpath-injection-cve-2026-22730/ https://t.co/KU01zxmHHi

    Post summary

    The tweet announces critical Spring AI vulnerabilities (CVE‑2026‑22729 and CVE‑2026‑22730) that enable access control bypass through JSONPath and SQL injection, urging users to apply updates.

    02021376
    10.7K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    CVE-2026-22729: JSONPath Injection in Spring AI’s PgVectorStore https://blog.securelayer7.net/cve-2026-22729-jsonpath-injection-spring-ai-pgvectorstore/

    Post summary

    The SecureLayer7 blog post announces a new CVE-2026-22729, describing a JSONPath Injection vulnerability in Spring AI’s PgVectorStore.

    02010412
    32.9K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High severity vulnerability in #spring AI. CVE-2026-22729 CVSS: 8.6. Authenticated users can bypass access controls and access unauthorised documents. Update to versions 1.0.4 and 1.1.3. More info: https://spring.io/security/cve-2026-22729 #Patch #Patch #Patch

    Post summary

    A high-severity CVE-2026-22729 in Spring AI allows authenticated users to bypass access controls; patches 1.0.4 and 1.1.3 are recommended and available.

    01001256
    7.2K followersView on X
  • dbugs@ptdbugs
    Disclosure

    CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter CVE: CVE-2026-22729 PT-Identifier: PT-2026-25939 Vendor: Vmware Product: Spring AI CVSS: 8.6 Credits: n/a Description: A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling attackers to inject arbitrary JSONPath logic and access unauthorized documents. This vulnerability affects applications using vector stores that extend AbstractFilterExpressionConverter for multi-tenant isolation, role-based access control, or document filtering based on metadata. The vulnerability occurs when user-supplied values in filter expressions are not escaped before being inserted into JSONPath queries. Special characters like ", ||, and && are passed through unescaped, allowing injection of arbitrary JSONPath logic that can alter the intended query semantics. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-22729 • https://spring.io/security/cve-2026-22729 #dbugs_vuln

    Post summary

    The post announces a new JSONPath injection flaw (CVE-2026-22729) in VMware Spring AI, detailing how authenticated users can inject JSONPath logic to bypass access controls, but it does not mention a PoC, active exploitation, or patch.

    01001146
    633 followersView on X
  • SecureLayer7@SecureLayer7
    General

    1. https://blog.securelayer7.net/cve-2026-25049/ 2. https://blog.securelayer7.net/cve-2026-22729-jsonpath-injection-spring-ai-pgvectorstore/

    Post summary

    The text consists solely of two URLs to blog posts about CVE-2026-25049 and CVE-2026-22729 (JSONPath injection in Spring AI pgVectorStore), with no additional context, technical details, or actionable information provided in the tweet/post text itself.

    0001054
    2.5K followersView on X
  • Abcas MCP Guard@abcas_mcp_guard
    Disclosure

    Spring AI users: CVE-2026-22729 (JSONPath Injection) and CVE-2026-22730 (SQL Injection) highlight that even "safe" frameworks need runtime monitoring. 🛡️ Don't trust inputs blindly. Secure your agentic workflows with MCP Guard. #MCPSecurity #SpringAI #AISecurity

    Post summary

    The post announces two CVEs—CVE-2026-22729 (JSONPath Injection) and CVE-2026-22730 (SQL Injection) in Spring AI—emphasizing the need for runtime monitoring.

    0001046
    11 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Java Spring AIにSQLインジェクションとJSONPathインジェクションの脆弱性(CVE-2026-22730、CVE-2026-22729) https://rocket-boys.co.jp/security-measures-lab/spring-ai-sql-injection-jsonpath-injection-cve-2026-22730-cve-2026-22729/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces the discovery of two new Java Spring AI vulnerabilities (CVE-2026-22730 and CVE-2026-22729) that involve SQL injection and JSONPath injection, linking to a detailed security report.

    00010166
    337 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-22729 - High A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. Use... https://www.thehackerwire.com/vulnerability/CVE-2026-22729/ https://t.co/lPxQ56IY1I

    Post summary

    High‑severity JSONPath injection in Spring AI’s AbstractFilterExpressionConverter enables authenticated users to bypass metadata controls, but no exploit or patch details are provided.

    0001038
    138 followersView on X
  • Prabhat Kashyap | prabhat.dev@prabhatdotdev
    Patch

    Spring AI just got hit with 2 critical CVEs (CVE-2026-22729, CVE-2026-22730). Injection flaws in filter expressions can bypass metadata-based access control in vector stores meaning cross-tenant data exposure. If you’re using spring-ai-vector-store or mariadb-store with user filters, you’re at risk. 👉 Upgrade immediately: 1.0.4 / 1.1.3 #AI #SpringBoot #CyberSecurity #RAG #LLM #DevSecOps

    Post summary

    Spring AI is impacted by two critical CVEs that enable injection attacks to bypass access controls across tenants; users are urged to upgrade immediately to patched releases.

    0000032
    8 followersView on X
  • Constantin Milos ♏@Tinolle infosec.exchange@Tinolle1955
    General

    https://blog.securelayer7.net/cve-2026-22729-jsonpath-injection-spring-ai-pgvectorstore/

    Post summary

    The link references CVE-2026-22729 (JSONPath injection in Spring AI PGVectorStore), but no explicit details, PoC, or patch information are present in the provided text.

    0000049
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22729 A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafte… https://www.cve.org/CVERecord?id=CVE-2026-22729

    Post summary

    A new JSONPath injection flaw (CVE‑2026‑22729) in Spring AI’s AbstractFilterExpressionConverter allows authenticated users to bypass metadata access controls, with no PoC or active exploitation noted.

    00000149
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2026-22729: CVE-2026-22729: JSONPath Inject... Spring AI's JSONPath injection lets attackers escape metadata filters with `", ||, &&` - turning tenant isolation into ... https://zerodaysignal.com/vulnerability/CVE-2026-22729 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the CVE-2026-22729 vulnerability – a JSONPath injection flaw in Spring AI that allows attackers to bypass metadata filters – without mentioning patches, PoCs, or active exploitation.

    0000050
    155 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22729 JSONPath Injection in Spring AI Enables Unauthorized Document Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22729

    Post summary

    CVE-2026-22729 is a JSONPath injection vulnerability in Spring AI that allows attackers to read unauthorized documents.

    0000039
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22729 - CVE-2026-22729: JSONPath Injection in Spring AI Vector Stores FilterExpressionConverter Intel Report: https://ift.tt/naB0AWQ

    Post summary

    The alert identifies CVE‑2026‑22729 as a JSONPath injection flaw in Spring AI Vector Stores, with a link to an Intel Report, but offers no additional exploitation, mitigation, or patch information.

    0000027
    335 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22729: HIGH] Vulnerability in Spring AI allows users to bypass access control with crafted filter expressions, enabling JSONPath injection and unauthorized document access.#cve,CVE-2026-22729,#cybersecurity https://cvefind.com/CVE-2026-22729

    Post summary

    The post discloses a high‑severity vulnerability in Spring AI that enables JSONPath injection through crafted filter expressions, allowing attackers to bypass access controls and access unauthorized documents.

    0000044
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_ai---

Explore more