Impact
The flaw lies in MongoDBChatMessageHistory’s failure to enforce at runtime that the session identifier is a simple string. When an untrusted identifier is passed to the framework, it is treated as a MongoDB query object instead of a literal value. An attacker who can call chat‑history functions can craft a session id that includes a MongoDB query operator, which then lets the attacker read, change, or erase another user’s stored conversation. The issue is a classic query‑injection that bypasses isolation between user sessions.
Affected Systems
This vulnerability affects the LangChain packages @langchain:mongodb and langchain-ai:langchainjs when they are older than version 1.3.1. All deployments that store multiple users’ histories in the same MongoDB collection are vulnerable unless the application strictly supplies server‑controlled, validated string identifiers.
Risk and Exploitability
The CVSS score is 6, indicating moderate risk. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to invoke chat‑history operations with a crafted session id; thus an attacker would need the ability to send that request to the application. If the attacker has access to the API that performs chat‑history operations, the exploited query injection can be executed without further privileges, giving the attacker unauthorized read and write capabilities against other users’ message history.
OpenCVE Enrichment