CVE-2026-41713: Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
(updated )
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41713 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →