Skip to main content

🪐 Backed by $16.5M to build the security workforce for the security workforce. Meet the new Cantina.

Vulnerability disclosure

Filter keys enable Cypher injection in Neo4j stores

CVE-2026-22743

Affected product
Spring AI
Severity
High
CVSS
7.5
Weakness
CWE-89
Published

Disclosure summary

CVE-2026-22743 is a high-severity CWE-89 vulnerability in Spring AI. Filter keys enable Cypher injection in Neo4j stores. Cantina reproduced the behavior, verified its security impact, and coordinated disclosure with the affected maintainer.

Verification standard

Cantina publishes a disclosure only after reproducing the behavior, validating its security impact, and coordinating remediation with the affected project.