HighVulnerabilityLLM-specific
CVE-2026-106119: LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-106119
- Published
- Record updated
Summary
LangChain versions before 1.3.1 let MongoDBChatMessageHistory accept an untrusted structured session identifier without enforcing the documented string type. When several users' histories share one MongoDB collection, the identifier is interpreted as a MongoDB query condition instead of a literal value. An attacker who can invoke chat-history operations can read, modify, or delete another user's conversation. Applications that use authenticated, server-controlled string identifiers are not affected.
Mitigation
Fixed in version 1.3.1.
Related items
- LowGHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text ValuesSame vendor · GitHub Advisory Database
- Info'The hottest skill on Wall Street’: Demand for this AI ability jumped 1,721% as banks embrace agentsSame vendor · CNBC Technology
- Medium Inside 90 days of attacks on AI infrastructureSame vendor · Wiz Research Blog
- InfoAustralian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and othersSame vendor · TechCrunch (Security)
- HighCVE-2026-72848: SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented…Same vendor · NVD/CVE Database