Vulnerability  ·  2026-10-07

LangChain JS MongoDBChatMessageHistory NoSQL injection — cross-user conversation read/modify/delete

VulnerabilityMedium impactGlobalCVE-2026-106119
MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime (CWE-943). When multiple users' histories share a MongoDB collection, the identifier is interpreted as a MongoDB query condition instead of a literal value, so an attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Fixed in @langchain/mongodb 1.3.1.
LangChain's MongoDB chat-memory is a default building block for persistent LLM conversation/RAG apps. The flaw lets one user reach other users' chat histories (prompts, contexts, possibly sensitive exchanges) and tamper with them — memory-poisoning the exact data an application feeds back into an LLM.
Supply a MongoDB operator object (e.g. $ne conditions) instead of a plain session string in a chat-history operation while sharing a collection with other users.
@langchain/mongodb < 1.3.1; langchainjs < 1.5.14
Upgrade to @langchain/mongodb 1.3.1 / langchainjs 1.5.14; ensure session identifiers are server-controlled strings.
NVD CVE-2026-106119GitHub advisory GHSA-m6rx-h84q-8r95secalerts.co LangChain analysis
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →