PT-2026-106840 · Langchain · Langchain

CVE-2026-106119

·

Published

2026-10-06

·

Updated

2026-10-08

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LangChain versions prior to 1.3.1
Description In the MongoDBChatMessageHistory component, the system fails to enforce the required string type for untrusted structured session identifiers at runtime. This allows a session identifier to be interpreted as a MongoDB query condition instead of a literal value when multiple users share a MongoDB collection. An attacker capable of invoking chat-history operations can read, modify, or delete conversation histories belonging to other users. This issue does not affect applications that utilize authenticated, server-controlled string identifiers.
Recommendations Update to version 1.3.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106119
GHSA-M6RX-H84Q-8R95

Affected Products

Langchain