{"id":"GHSA-m6rx-h84q-8r95","summary":"LangChain: MongoDBChatMessageHistory query injection can allow cross-session access","details":"## Impact\n\n`MongoDBChatMessageHistory` did not enforce the documented string type for session identifiers at runtime. In affected applications, a structured session identifier could be interpreted as a MongoDB query condition rather than as a literal identifier.\n\nApplications are affected when they pass untrusted session identifier input to `MongoDBChatMessageHistory` and store multiple users’ histories in the same collection. An attacker who can invoke chat-history operations may be able to read, modify, or delete another user’s stored conversation.\n\nApplications that derive the session identifier from an authenticated, server-controlled value and enforce its type are not affected by this path.\n\n## Patches\n\nThe issue is fixed in `@langchain/mongodb` version **1.3.1**.\n\nUsers of affected versions should upgrade to version 1.3.1 or later. The patched version validates session identifiers at runtime and ensures they are compared as literal values in MongoDB queries.\n\n## Workarounds\n\nIf an immediate upgrade is not possible, applications must reject session identifiers that are not non-empty strings. Session identifiers should be derived from an authenticated, server-controlled value and must not be passed directly from an untrusted request field.\n\nUpgrading remains the recommended remediation.","aliases":["CVE-2026-106119"],"modified":"2026-10-08T18:00:08.902627724Z","published":"2026-10-08T17:52:22Z","database_specific":{"nvd_published_at":"2026-10-06T19:17:42Z","cwe_ids":["CWE-943"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T17:52:22Z"},"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchainjs/security/advisories/GHSA-m6rx-h84q-8r95"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106119"},{"type":"WEB","url":"https://github.com/langchain-ai/langchainjs/pull/11672"},{"type":"WEB","url":"https://github.com/langchain-ai/langchainjs/commit/946e3d856ff1f8ce7f7b9374c83f680a6ada79af"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchainjs"},{"type":"WEB","url":"https://github.com/langchain-ai/langchainjs/releases/tag/@langchain/mongodb@1.3.1"}],"affected":[{"package":{"name":"@langchain/mongodb","ecosystem":"npm","purl":"pkg:npm/%40langchain/mongodb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.3.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-m6rx-h84q-8r95/GHSA-m6rx-h84q-8r95.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}