
🔵 @langchain/#redis, RediSearch Filter Injection, #CVE-2026-105799 (Low) -DC-Oct2026-2776 https://dailycve.com/langchain-redis-redisearch-filter-injection-cve-2026-105799-low-dc-oct2026-2776/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
LangChain is a framework for building LLM-powered applications. Prior to 1.1.1, @langchain/redis does not escape attacker-controlled values in structured RediSearch TAG filters and structured RediSearch TEXT filters, allowing injected RediSearch syntax to alter or broaden the generated search query. When an application uses an attacker-influenceable filter as a tenant or document-access boundary, the modified query can expose indexed documents outside the attacker's intended scope. This issue is fixed in version 1.1.1.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔵 @langchain/#redis, RediSearch Filter Injection, #CVE-2026-105799 (Low) -DC-Oct2026-2776 https://dailycve.com/langchain-redis-redisearch-filter-injection-cve-2026-105799-low-dc-oct2026-2776/