CVE-2026-105799 PUBLISHED

LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values

Assigner: GitHub_M
Reserved: 05.10.2026 Published: 06.10.2026 Updated: 06.10.2026

LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor langchain-ai
Product langchainjs
Versions
  • Version < 1.1.1 is affected
Vendor @langchain
Product redis
Versions
  • Version < 1.1.1 is affected

References

Problem Types

  • CWE-943: Improper Neutralization of Special Elements in Data Query Logic CWE