Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1. | |
| Title | LangChain: MongoDBChatMessageHistory query injection can allow cross-session access | |
| Weaknesses | CWE-943 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T19:45:43.997Z
Reserved: 2026-10-06T15:33:55.333Z
Link: CVE-2026-106119
Updated: 2026-10-06T19:45:09.290Z
Status : Awaiting Analysis
Published: 2026-10-06T19:17:42.800
Modified: 2026-10-06T20:17:17.820
Link: CVE-2026-106119
No data.
OpenCVE Enrichment
Updated: 2026-10-06T20:00:06Z