CVE-2026-41713
HIGH EPSS 12.2%
Published May 12, 20261mo ago · Modified Jun 17, 20262w ago
8.2 CVSS 3.1
Published May 12, 2026 1mo ago
Last Modified Jun 17, 2026 2w ago
Description
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity High
Availability None
Threat Intelligence
EPSS Exploit Probability
12.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-1336
Affected Products 2
References 2
- nvd.nist.gov https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N&version=3.1
- spring.io https://spring.io/security/cve-2026-41713
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.