Impact
LangChain MongoDB allows NoSQL operator injection in the MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() functions. The vulnerability arises because filter dictionaries are combined into MongoDB queries without recursively rejecting keys that start with $. An attacker who can control a filter argument through HTTP query parameters, request body fields, or agent tool arguments can inject MongoDB Query Language operators such as $regex or $where. In a multi‑tenant deployment that uses these filters to enforce per‑user or per‑tenant isolation, the injected operators can bypass the intended equality checks and expose checkpoint or store data belonging to other tenants, leading to serious confidentiality breaches.
Affected Systems
The flaw affects three libraries distributed by langchain‑ai: langchain‑mongodb, langgraph‑checkpoint‑mongodb, and langgraph‑store‑mongodb. Versions of langgraph‑checkpoint‑mongodb prior to 0.3.0 and langgraph‑store‑mongodb prior to 0.4.0 are vulnerable. Any deployment that exposes the MongoDBSaver.list() or MongoDBStore.search() APIs to authenticated callers, especially in a multi‑tenant environment, is at risk. The core LangChain MongoDB integration package can also participate if the underlying libraries are unpatched.
Risk and Exploitability
The CVSS score of 7.7 categorizes this as High severity. The EPSS score of <1% indicates a very low but nonzero probability of exploitation. The likely attack vector requires an authenticated caller who can influence filter arguments; attackers could then inject MongoDB Query Language operators to deviate from the intended tenant boundary and expose sensitive data. Once the vulnerable code is triggered, the impact is immediate data leakage across tenants, which can lead to regulatory violations, operational disruptions, and loss of customer trust.
OpenCVE Enrichment
Github GHSA