Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106119— LangChain: MongoDBChatMessageHistory query injection can allow cross-session access

Quick assessment

Affected
langchain-ai langchainjs
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LangChain 是一个用于构建大语言模型(LLM)驱动应用的框架。在 1.3.1 版本之前,MongoDBChatMessageHistory 组件在运行时未对不可信的、结构化的会话标识符强制执行文档中声明的字符串类型。这导致当多个用户的历史记录存储在同一 MongoDB 集合中时,该标识符可能被解释为 MongoDB 查询条件,而非字面量值。因此,攻击者若能调用聊天历史操作,即可读取、修改或删除其他用户存储的对话数据。对于使用经过身份验证、由服务器控制的字符串标识符的应用程序,则不受此漏洞影响。该问题已在 1

CVSS 6.0 · Medium EPSS 0.46% · P38

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProduct Version RangeStatus
@langchain mongodb < 1.3.1 affected
langchain-ai langchainjs < 1.5.14 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106119

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LangChain: MongoDBChatMessageHistory query injection can allow cross-session access
Source: CVE Program / CVE List V5
Vulnerability Description
LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
数据查询逻辑中特殊元素的不当中和
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
langchain-ai langchainjs < 1.5.14 -
@langchain mongodb < 1.3.1 -

II. Public POCs for CVE-2026-106119

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106119

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-106119 (1)

Vendor Advisories for CVE-2026-106119 (1)

Other References for CVE-2026-106119 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-106119

No comments yet


Leave a comment