Vulnerability Intelligence Report
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values
CVE-2026-105799
LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.
No Active Exploit Signals
CVSS Base Score
2.3
LOW
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-943 ↗CWE-943: Improper Neutralization of Special Elements in Data Query Logic
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| langchain-ai | langchainjs | < 1.1.1 (affected) |
| @langchain | redis | < 1.1.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-10-05T20:37:19 |
| Published | 2026-10-06T14:45:38 |
| Last Updated | 2026-10-06T17:39:51 |
Community Chatter & Buzz