CVE-2026-105799: @langchain Redis
Low severity, CVSS 2.3. EPSS: 0.3% chance of exploitation in the next 30 days.
LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.
Affected products
- @langchain Redis: before 1.1.1 (fixed in 1.1.1)
- Langchain-Ai Langchainjs: before 1.1.1 (fixed in 1.1.1)
Published 2026-10-06. Last modified 2026-10-06.