{"data":{"id":"d7d83547-f87f-4f35-b2f6-6b5f24702ed1","title":"CVE-2026-106119: LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not…","summary":"LangChain versions before 1.3.1 let MongoDBChatMessageHistory accept an untrusted structured session identifier without enforcing the documented string type. When several users' histories share one MongoDB collection, the identifier is interpreted as a MongoDB query condition instead of a literal value. An attacker who can invoke chat-history operations can read, modify, or delete another user's conversation. Applications that use authenticated, server-controlled string identifiers are not affected.","solution":"Fixed in version 1.3.1.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106119","publishedAt":"2026-10-06T19:17:42.800Z","cveId":"CVE-2026-106119","cweIds":["CWE-943"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":["@langchain/mongodb@<= 1.3.0 (fixed: 1.3.1)"],"affectedPackageNames":["@langchain/mongodb"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LangChain","MongoDBChatMessageHistory"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"LangChain MongoDBChatMessageHistory query injection via session identifier","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00463,"epssCheckedAt":"2026-10-10T02:57:39.298Z","kevDateAdded":null,"advisoryAliases":["GHSA-m6rx-h84q-8r95"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:42:48.272Z","patchAvailable":true,"disclosureDate":"2026-10-06T19:17:42.800Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":true,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}