Impact
A malicious user can craft input that is stored in the PromptChatMemoryAdvisor conversation memory and later interpreted by the model in an unintended way. The affected advisor leads to manipulation of model behavior across conversation turns, effectively allowing a user to influence or hijack the model’s responses. This flaw is a form of prompt injection that could degrade confidentiality or integrity of the application’s decisions and outputs.
Affected Systems
The vulnerability affects VMware:Spring AI PromptChatMemoryAdvisor. No specific affected versions are provided in the current data, so any deployed instance of this advisor should be inspected for the presence of the flaw.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity assessment. EPSS data are not available, and the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog, implying the broader threat landscape for this issue is currently unknown. The attack vector is inferred to be remote, as any user providing input that is persisted in memory could trigger the misuse of the model without needing privileged access. The exploitation requires only the ability to supply crafted input to the advisor, making the vulnerability highly accessible to legitimate users.
OpenCVE Enrichment