Impact
LangChain4j is a Java library for building LLM‑powered applications on the JVM. Prior to 1.2.1‑beta8, 1.5.1‑beta11, 1.11.8‑beta19, and 1.16.3‑beta26, the MariaDB and pgvector embedding stores build metadata‑filter SQL by string‑concatenating filter keys, and in MariaDB string values, directly into the query without adequate escaping. A crafted metadata key in EmbeddingSearchRequest.filter() can break out of its SQL context and inject arbitrary SQL into the statements executed by the stores' search and removeAll(Filter) operations, enabling blind data exfiltration, denial of service via sleep functions, and deletion of arbitrary rows through removeAll(Filter). The issue is fixed in langchain4j‑mariadb and langchain4j‑pgvector versions 1.2.1‑beta8, 1.5.1‑beta11, 1.11.8‑beta19, and 1.16.3‑beta26.
Affected Systems
Affected products are the Java libraries langchain4j‑mariadb and langchain4j‑pgvector under the langchain4j vendor. Versions before 1.2.1‑beta8, 1.5.1‑beta11, 1.11.8‑beta19, and 1.16.3‑beta26 are vulnerable; those later versions include the fix.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while the EPSS score of < 1% suggests a very low, but non‑zero, likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but it can be triggered— untrusted input are at risk. Exploitation requires only the ability to invoke EmbeddingSearchRequest.filter(), making it likely in web services or APIs that front the library.
OpenCVE Enrichment
Github GHSA