Detects Spring AI applications where the SimpleVectorStore filter expression converter interpolates user-controlled metadata filter key names directly into SpEL templates without sanitization. An unauthenticated attacker can inject arbitrary Spring Expression Language via the filter key parameter, breaking out of the #metadata['...'] context to execute arbitrary Java code including T(java.lang.Runtime).getRuntime().exec() for full Remote Code Execution. Affects Spring AI 1.0.0 through 1.0.4 and 1.1.0-M1 through 1.1.3.
Is your app exploitable through CVE-2026-22738?
Scan your domain free