CVE-2026-40966

MEDIUM

VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltration

Title source: cna
STIX 2.1

Description

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conversationId. Only applications that use VectorStoreChatMemoryAdvisor and pass user-supplied input as a conversationId are affected.

Scores

CVSS v3 5.9
EPSS 0.0003
EPSS Percentile 10.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (3)
VMware/Spring AI 1.0.0 - 1.0.6
VMware/Spring AI 1.1.0 - 1.1.5
vmware/spring_ai 1.0.0 - 1.0.6
Published Apr 28, 2026
Tracked Since Apr 28, 2026