Query Injection Vulnerability in Redis Checkpoint Implementation for LangGraph by LangChain
CVE-2026-27022
What is CVE-2026-27022?
A query injection vulnerability is present in the @langchain/langgraph-checkpoint-redis package, which serves as the Redis checkpoint and store implementation for LangGraph. The vulnerability is due to inadequate handling of user-supplied filter keys and values during RediSearch query construction in the RedisSaver and ShallowRedisSaver classes. By directly interpolating unescaped user data, the query logic can be manipulated, allowing attackers to potentially bypass access controls. Users are advised to upgrade to version 1.0.2 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
langgraphjs < 1.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
