Injection Flaw in LangChain Redis Plugin Impacts Applications
CVE-2026-105799

2.3LOW

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105799?

The LangChain Redis plugin, prior to version 1.1.1, contains a vulnerability that allows for the injection of unescaped attacker-controlled values within structured RediSearch TAG and TEXT filters. This oversight permits an adversary to modify the generated search queries, potentially altering the access scopes of indexed documents. Consequently, it could lead to unauthorized access to sensitive information that exceeds the intended permissions, especially when these manipulated queries are utilized as filters for tenant or document access boundaries. The issue was addressed in version 1.1.1.

Affected Version(s)

langchainjs < 1.1.1

redis < 1.1.1

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.