Description
LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1.
Published: 2026-10-06
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Data Breach: unauthorized read, modify, delete of conversation history
Action: Apply Patch
AI Analysis

Impact

The flaw lies in MongoDBChatMessageHistory’s failure to enforce at runtime that the session identifier is a simple string. When an untrusted identifier is passed to the framework, it is treated as a MongoDB query object instead of a literal value. An attacker who can call chat‑history functions can craft a session id that includes a MongoDB query operator, which then lets the attacker read, change, or erase another user’s stored conversation. The issue is a classic query‑injection that bypasses isolation between user sessions.

Affected Systems

This vulnerability affects the LangChain packages @langchain:mongodb and langchain-ai:langchainjs when they are older than version 1.3.1. All deployments that store multiple users’ histories in the same MongoDB collection are vulnerable unless the application strictly supplies server‑controlled, validated string identifiers.

Risk and Exploitability

The CVSS score is 6, indicating moderate risk. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an attacker to invoke chat‑history operations with a crafted session id; thus an attacker would need the ability to send that request to the application. If the attacker has access to the API that performs chat‑history operations, the exploited query injection can be executed without further privileges, giving the attacker unauthorized read and write capabilities against other users’ message history.

Generated by OpenCVE AI on October 6, 2026 at 19:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade @langchain:mongodb and langchain‑ai:langchainjs to version 1.3.1 or newer, which restores string type enforcement on session identifiers.
  • Ensure that all session identifiers come from a trusted source or are properly sanitized; confirmation that the framework treats them as literal values is essential before passing them to any chat‑history method.
  • If an upgrade cannot be performed immediately, isolate session histories—use distinct MongoDB collections for each user or enforce application‑level access controls that verify the authenticated user matches the session id before any read or write operation.

Generated by OpenCVE AI on October 6, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1.
Title LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
Weaknesses CWE-943
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:45:43.997Z

Reserved: 2026-10-06T15:33:55.333Z

Link: CVE-2026-106119

cve-icon Vulnrichment

Updated: 2026-10-06T19:45:09.290Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:42.800

Modified: 2026-10-06T20:17:17.820

Link: CVE-2026-106119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:00:06Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic