What happened
MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime (CWE-943). When multiple users' histories share a MongoDB collection, the identifier is interpreted as a MongoDB query condition instead of a literal value, so an attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Fixed in @langchain/mongodb 1.3.1.
Why it matters
LangChain's MongoDB chat-memory is a default building block for persistent LLM conversation/RAG apps. The flaw lets one user reach other users' chat histories (prompts, contexts, possibly sensitive exchanges) and tamper with them — memory-poisoning the exact data an application feeds back into an LLM.
Attack vector
Supply a MongoDB operator object (e.g. $ne conditions) instead of a plain session string in a chat-history operation while sharing a collection with other users.
Affected systems
@langchain/mongodb < 1.3.1; langchainjs < 1.5.14
Mitigation
Upgrade to @langchain/mongodb 1.3.1 / langchainjs 1.5.14; ensure session identifiers are server-controlled strings.