CVE-2026-105799
LOW
2,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.
943
Improper Neutralization of Special Elements in Data Query Logic
IncompleteCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Availability
Access Control
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Modify Application Data
Varies By Context
Applicable Platforms
All platforms may be affected
https://github.com/langchain-ai/langchainjs/commit/880e3969ea643a2147777a4d5e8b…
https://github.com/langchain-ai/langchainjs/pull/10701
https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/[email protected]
https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-5x6v-p487-…