SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Spring AI Vector Stores JSONPath Injection

Category: WEB-ATTACKS      

A JSONPath injection vulnerability in Spring AI's AbstractFilterExpressionConverter allows authenticated users to bypass metadata-based access controls through crafted filter expressions. User-controlled input passed to FilterExpressionBuilder is concatenated into JSONPath queries without proper escaping, enabling attackers to inject arbitrary JSONPath logic and access unauthorized documents.


Relevant Information