← Back to CVE List
CVE-2026-41713NVD
Vulnerability Summary
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.
CVSS v3.1 Base Metrics — Score 8.2 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Vmware Spring Ai >= 1.0.0 and < 1.0.7
- Vmware Spring Ai >= 1.1.0 and < 1.1.6
- Vmware Spring Ai 1.0.7
- Vmware Spring Ai 1.1.6