๐Ÿ” CVE Alert

CVE-2026-27022

MEDIUM 6.5

RediSearch Query Injection in @langchain/langgraph-checkpoint-redis

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.

CWE CWE-74
Vendor langchain-ai
Product langgraphjs
Published Feb 20, 2026
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for langchain-ai langgraphjs

Be the first to know when new medium vulnerabilities affecting langchain-ai langgraphjs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

langchain-ai / langgraphjs
< 1.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/langchain-ai/langgraphjs/security/advisories/GHSA-5mx2-w598-339m github.com: https://github.com/langchain-ai/langgraphjs/pull/1943 github.com: https://github.com/langchain-ai/langgraphjs/commit/814c76dc3938d0f6f7e17ca3bc11d6a12270b2a1 github.com: https://github.com/langchain-ai/langgraphjs/releases/tag/@langchain/[email protected]