{"data":{"id":"d45ccfb8-996c-4984-aab2-ae3fd0461dc1","title":"GHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values","summary":"`@langchain/redis` versions through 1.1.0 did not properly escape values used to build structured RediSearch TAG and TEXT filters. An attacker who controls values passed into these filters can inject RediSearch syntax, altering or broadening the search query and potentially exposing indexed documents outside their intended scope where the filter serves as a tenant or document-access boundary.","solution":"Upgrade to `@langchain/redis` 1.1.1 or later.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-5x6v-p487-7qh2","publishedAt":"2026-10-06T15:32:34.000Z","cveId":"CVE-2026-105799","cweIds":null,"cvssScore":null,"cvssSeverity":"low","severity":"low","attackType":["other"],"issueType":"vulnerability","affectedPackages":["@langchain/redis@<= 1.1.0 (fixed: 1.1.1)"],"affectedPackageNames":["@langchain/redis"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LangChain","@langchain/redis","RediSearch"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00278,"epssCheckedAt":"2026-10-10T02:57:39.298Z","kevDateAdded":null,"advisoryAliases":["GHSA-5x6v-p487-7qh2"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-06T15:32:34.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}