← Back to CVE List
CVE-2026-106119NVD
Vulnerability Summary
LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1.
CVSS v4.0 Base Metrics — Score 6.0 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsPresent
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- langchain-ai langchainjs >= < 1.5.14
- @langchain mongodb >= < 1.3.1
Not provided by cveorg for this CVE.
External References
- https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-m6rx-h84q-8r95
- https://github.com/langchain-ai/langchainjs/pull/11672
- https://github.com/langchain-ai/langchainjs/commit/946e3d856ff1f8ce7f7b9374c83f680a6ada79af
- https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/mongodb@1.3.1