---
id: CVE-2026-105799
title: LangChain is a framework for building LLM-powered applications
summary: >-
  LangChain is a framework for building LLM-powered applications. Prior to
  1.1.1, @langchain/redis does not escape attacker-controlled values in
  structured RediSearch TAG filters and structured RediSearch TEXT filters,
  allowing injected Re…
severity: low
cvss: 2.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-943
vendor: langchain
product: '@langchain/redis'
affected:
  - '@langchain/redis <= 1.1.0'
patched:
  - '@langchain/redis 1.1.1'
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T15:19:48.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105799'
references:
  - url: >-
      https://github.com/langchain-ai/langchainjs/commit/880e3969ea643a2147777a4d5e8bd606a697edf7
    label: security-advisories@github.com
  - url: 'https://github.com/langchain-ai/langchainjs/pull/10701'
    label: security-advisories@github.com
  - url: >-
      https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/redis@1.1.1
    label: security-advisories@github.com
  - url: >-
      https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-5x6v-p487-7qh2
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105799'
  - url: 'https://github.com/advisories/GHSA-5x6v-p487-7qh2'
tags:
  - nvd
  - ghsa
  - npm
  - cve.org
aliases:
  - GHSA-5x6v-p487-7qh2
ecosystem: npm
cvssSource: cna
ingestedAt: '2026-10-06T15:01:49.302Z'
---

## Overview

LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-105799)

Affected packages:

- `@langchain/redis <= 1.1.0`

Patched in:

- `@langchain/redis 1.1.1`

Source: https://github.com/advisories/GHSA-5x6v-p487-7qh2
