Skip to content
LowVulnerability

GHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values

Published
Record updated
View JSON
Affected
  • @langchain/redis <= 1.1.0
Fixed in
1.1.1
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

`@langchain/redis` versions through 1.1.0 did not properly escape values used to build structured RediSearch TAG and TEXT filters. An attacker who controls values passed into these filters can inject RediSearch syntax, altering or broadening the search query and potentially exposing indexed documents outside their intended scope where the filter serves as a tenant or document-access boundary.

Mitigation

Upgrade to `@langchain/redis` 1.1.1 or later.