CVE-2026-27022
RediSearch Query Injection in @langchain/langgraph-checkpoint-redis
@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.
| CWE | CWE-74 |
| Vendor | langchain-ai |
| Product | langgraphjs |
| Published | Feb 20, 2026 |
| Last Updated | Feb 24, 2026 |
Get instant alerts for langchain-ai langgraphjs
Be the first to know when new medium vulnerabilities affecting langchain-ai langgraphjs are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N