https://reddit.com/r/netsec/comments/1rxz7tl/cve202622729_jsonpath_injection_in_spring_ais/: CVE-2026-22729: JSONPath Injection in Spring AI’s PgVectorStore
Published Mar 19, 2026
·Updated
Affected Software
1 affected component
Spring Spring AI PgVectorStore
Frequently Asked Questions
1
What is the severity of CVE-2026-22729?
CVE-2026-22729 is categorized as a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2026-22729?
To fix CVE-2026-22729, update to the latest version of Spring AI that addresses this vulnerability.
3
What systems are affected by CVE-2026-22729?
CVE-2026-22729 affects applications utilizing Spring AI's PgVectorStore for JSONPath parsing.
4
Can CVE-2026-22729 lead to data loss?
Yes, CVE-2026-22729 can potentially lead to data loss if an attacker exploits the vulnerability.
5
Is CVE-2026-22729 related to other vulnerabilities in Spring?
CVE-2026-22729 is specific to Spring AI's PgVectorStore and should be evaluated independently of other vulnerabilities.