CVE-2026-27022: Langchain-Ai Langgraphjs
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.
Affected products
- Langchain-Ai Langgraphjs: before 1.0.2 (fixed in 1.0.2)
Published 2026-02-20. Last modified 2026-06-17.