Injection Flaw in LangChain Redis Plugin Impacts Applications
CVE-2026-105799
2.3LOW
What is CVE-2026-105799?
The LangChain Redis plugin, prior to version 1.1.1, contains a vulnerability that allows for the injection of unescaped attacker-controlled values within structured RediSearch TAG and TEXT filters. This oversight permits an adversary to modify the generated search queries, potentially altering the access scopes of indexed documents. Consequently, it could lead to unauthorized access to sensitive information that exceeds the intended permissions, especially when these manipulated queries are utilized as filters for tenant or document access boundaries. The issue was addressed in version 1.1.1.
Affected Version(s)
langchainjs < 1.1.1
redis < 1.1.1
