Vulnerability  ·  2026-10-07

LangChain Redis structured RediSearch query injection (CVE-2026-105799)

VulnerabilityLow impactGlobalCVE-2026-105799
@langchain/redis does not escape attacker-controlled values in structured RediSearch TAG and TEXT filters (CWE-943), allowing injected RediSearch syntax to alter or broaden the generated search query. Where such a filter acts as a tenant/doc-access boundary, the modified query can expose indexed documents outside the intended scope. Fixed in 1.1.1.
Redis vector/structured search is used for RAG memory and access-scoped retrieval; query injection can widen retrieval past intended document boundaries.
Inject RediSearch operators into a TAG/TEXT filter value to broaden the generated query beyond the intended document scope.
@langchain/redis < 1.1.1 (langchainjs < 1.1.1)
Upgrade to @langchain/redis 1.1.1; treat filter values as opaque and escape accordingly.
NVD CVE-2026-105799GitHub advisory GHSA-5x6v-p487-7qh2
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →