What happened
@langchain/redis does not escape attacker-controlled values in structured RediSearch TAG and TEXT filters (CWE-943), allowing injected RediSearch syntax to alter or broaden the generated search query. Where such a filter acts as a tenant/doc-access boundary, the modified query can expose indexed documents outside the intended scope. Fixed in 1.1.1.
Why it matters
Redis vector/structured search is used for RAG memory and access-scoped retrieval; query injection can widen retrieval past intended document boundaries.
Attack vector
Inject RediSearch operators into a TAG/TEXT filter value to broaden the generated query beyond the intended document scope.
Affected systems
@langchain/redis < 1.1.1 (langchainjs < 1.1.1)
Mitigation
Upgrade to @langchain/redis 1.1.1; treat filter values as opaque and escape accordingly.