LowVulnerability
GHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
- Identifiers
- CVE-2026-105799GHSA-5x6v-p487-7qh2
- Published
- Record updated
- Affected
- @langchain/redis <= 1.1.0
- Fixed in
- 1.1.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
`@langchain/redis` versions through 1.1.0 did not properly escape values used to build structured RediSearch TAG and TEXT filters. An attacker who controls values passed into these filters can inject RediSearch syntax, altering or broadening the search query and potentially exposing indexed documents outside their intended scope where the filter serves as a tenant or document-access boundary.
Mitigation
Upgrade to `@langchain/redis` 1.1.1 or later.
Related items
- HighCVE-2026-106119: LangChain MongoDBChatMessageHistory query injection via session identifierSame vendor · NVD/CVE Database
- HighGHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decoratorsSame vendor · GitHub Advisory Database
- HighCVE-2026-72848: SitemapLoader nested sitemap entries bypass restrict_to_same_domainSame vendor · NVD/CVE Database
- HighGHSA-533j-2v4q-mw5h: LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposureSame vendor · GitHub Advisory Database
- MediumGHSA-jfj5-wrj9-63x4: langgraph-api: Incomplete assistant authorization in LangGraph Server run creationSame vendor · GitHub Advisory Database