Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5x6v-p487-7qh2 | LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values |
Tue, 06 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1. | |
| Title | LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values | |
| Weaknesses | CWE-943 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:39:51.463Z
Reserved: 2026-10-05T20:37:19.364Z
Link: CVE-2026-105799
No data.
Status : Awaiting Analysis
Published: 2026-10-06T15:17:17.030
Modified: 2026-10-06T15:19:48.933
Link: CVE-2026-105799
No data.
OpenCVE Enrichment
No data.
-
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
Github GHSA