Description
LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively rejecting keys prefixed with $. An authenticated caller who controls a filter argument through HTTP query parameters, request body fields, or agent tool arguments can inject MongoDB Query Language operators such as $regex or $where. In a multi-tenant deployment that uses the filter to enforce per-user or per-tenant isolation, injected operators can bypass intended equality filtering and expose other tenants' checkpoint or store data. Filters constructed entirely from trusted server-side values have lower practical risk. This issue is fixed in langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0.
Published: 2026-09-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑tenant data exposure
Action: Apply Patch
AI Analysis

Impact

LangChain MongoDB allows NoSQL operator injection in the MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() functions. The vulnerability arises because filter dictionaries are combined into MongoDB queries without recursively rejecting keys that start with $. An attacker who can control a filter argument through HTTP query parameters, request body fields, or agent tool arguments can inject MongoDB Query Language operators such as $regex or $where. In a multi‑tenant deployment that uses these filters to enforce per‑user or per‑tenant isolation, the injected operators can bypass the intended equality checks and expose checkpoint or store data belonging to other tenants, leading to serious confidentiality breaches.

Affected Systems

The flaw affects three libraries distributed by langchain‑ai: langchain‑mongodb, langgraph‑checkpoint‑mongodb, and langgraph‑store‑mongodb. Versions of langgraph‑checkpoint‑mongodb prior to 0.3.0 and langgraph‑store‑mongodb prior to 0.4.0 are vulnerable. Any deployment that exposes the MongoDBSaver.list() or MongoDBStore.search() APIs to authenticated callers, especially in a multi‑tenant environment, is at risk. The core LangChain MongoDB integration package can also participate if the underlying libraries are unpatched.

Risk and Exploitability

The CVSS score of 7.7 categorizes this as High severity. The EPSS score of <1% indicates a very low but nonzero probability of exploitation. The likely attack vector requires an authenticated caller who can influence filter arguments; attackers could then inject MongoDB Query Language operators to deviate from the intended tenant boundary and expose sensitive data. Once the vulnerable code is triggered, the impact is immediate data leakage across tenants, which can lead to regulatory violations, operational disruptions, and loss of customer trust.

Generated by OpenCVE AI on September 20, 2026 at 23:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade langgraph-checkpoint-mongodb to 0.3.0 or later and langgraph-store-mongodb to 0.4.0 or later to apply the security fix.
  • Validate all filter input on the server side to reject any key beginning with $$ before constructing MongoDB queries.
  • Restrict API access to only authorized tenant contexts and enforce strict tenant isolation logic at the application level.

Generated by OpenCVE AI on September 20, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-533j-2v4q-mw5h LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively rejecting keys prefixed with $. An authenticated caller who controls a filter argument through HTTP query parameters, request body fields, or agent tool arguments can inject MongoDB Query Language operators such as $regex or $where. In a multi-tenant deployment that uses the filter to enforce per-user or per-tenant isolation, injected operators can bypass intended equality filtering and expose other tenants' checkpoint or store data. Filters constructed entirely from trusted server-side values have lower practical risk. This issue is fixed in langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0.
Title LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
Weaknesses CWE-943
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:06:14.744Z

Reserved: 2026-06-16T16:44:00.625Z

Link: CVE-2026-55253

cve-icon Vulnrichment

Updated: 2026-09-14T19:20:52.636Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:17:55.500

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-55253

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:45:06Z

Weaknesses
  • CWE-943

    Improper Neutralization of Special Elements in Data Query Logic