A critical SQL injection vulnerability in Spring AI's MariaDBFilterExpressionConverter allows attackers to bypass metadata-based access controls and execute arbitrary SQL commands. The vulnerability exists due to missing input sanitization.
| Vendor | Product | Versions |
|---|---|---|
| vmware | spring_ai | < 1.0.4, < 1.1.3 |