CVE-2026-105799Low· 2.3▾ SunlitLangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected Re…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
@langchain/redis <= 1.1.0Patched in:
@langchain/redis 1.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48121Medium· 6.7@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage
CVE-2026-105681Medium· 6.5Ghost is a Node.js content management system
CVE-2026-105652Low· 3.1Ghost is a Node.js content management system
CVE-2026-105675High· 7.5Ghost is a Node.js content management system
CVE-2026-104956Medium· 5.3Plane is an open-source project management tool
CVE-2026-73976High· 7.1djehuty is a research data repository system developed by 4TU.ResearchData