PT-2026-106840 · Langchain · Langchain
CVE-2026-106119
·
Published
2026-10-06
·
Updated
2026-10-08
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LangChain versions prior to 1.3.1
Description
In the
MongoDBChatMessageHistory component, the system fails to enforce the required string type for untrusted structured session identifiers at runtime. This allows a session identifier to be interpreted as a MongoDB query condition instead of a literal value when multiple users share a MongoDB collection. An attacker capable of invoking chat-history operations can read, modify, or delete conversation histories belonging to other users. This issue does not affect applications that utilize authenticated, server-controlled string identifiers.Recommendations
Update to version 1.3.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langchain