NoSQL Injection Vulnerability in LangGraph.js Checkpoint Implementation by LangChain
CVE-2026-48121
Key Information:
- Vendor
Langchain-ai
- Status
- Vendor
- CVE Published:
- 4 August 2026
Badges
What is CVE-2026-48121?
The LangGraph.js CheckpointSaver implementation utilizing MongoDB storage is susceptible to a NoSQL injection vulnerability. This issue arises due to the lack of type enforcement when passing checkpoint identifiers from config.configurable into MongoDB queries in the MongoDBSaver.getTuple() method. An attacker can exploit this vulnerability by submitting object payloads, such as MongoDB operators contrary to expected string inputs, leading to unintended query interpretations. This can result in the leakage of sensitive checkpoints, including pending writes, across multi-tenant environments. To mitigate risks, it is essential to ensure that untrusted inputs are validated or coerced to strings before processing. Applications that adhere to schema validation and only utilize server-issued string identifiers remain unaffected. The vulnerability has been addressed in version 1.3.1.
Affected Version(s)
langgraphjs < 1.3.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
