Listen to this Post
CVE-2026-105799 is a query injection vulnerability in the @langchain/redis integration of the LangChain framework. The flaw resides in the way the package constructs structured RediSearch TAG and TEXT filters. Prior to version 1.1.1, @langchain/redis failed to properly escape attacker-controlled values that are embedded into these filters. RediSearch, the search engine module for Redis, uses a specific query language where special characters like quotes, parentheses, and logical operators such as OR and AND have syntactic meaning. Because LangChain did not neutralize these characters before passing the filter to the Redis driver, an attacker who can influence the values used in a filter can inject arbitrary RediSearch syntax. This allows the attacker to alter or broaden the resulting search query. The most severe consequence occurs in multi-tenant applications where a filter is intended to act as a tenant or document-access boundary. For example, if an application uses a filter to restrict results to a specific tenant ID, an attacker could inject logic that bypasses this restriction, effectively widening the scope of the returned data set. This can expose indexed documents belonging to other tenants or users, leading to a breach of confidentiality and a compromise of the application’s fundamental security model. The vulnerability is classified as CWE-943, Improper Neutralization of Special Elements in Data Query Logic. It is similar in nature to SQL injection, but specific to the RediSearch query language. The issue was fixed in version 1.1.1, which escapes RediSearch special characters, validates field names and structured filter types, and applies these protections across fluent filter builders and custom-schema query construction. The CVSS 4.0 base score is 2.3, rated as Low severity. The vulnerability was reported by @thesanjok and @shovanchakraborty. Users of @langchain/redis through version 1.1.0 are affected and should upgrade immediately.
DailyCVE Form:
Platform: @langchain/redis
Version: through 1.1.0
Vulnerability: RediSearch Filter Injection
Severity: Low
date: 2026-10-06
Prediction: 2026-04-15
What Undercode Say:
npm install @langchain/[email protected]
redis-cli FT.SEARCH idx “@tenant:{attacker_controlled_value}”
node -e “const { RedisVectorStore } = require(‘@langchain/redis’); const filter = { tenant: ‘value) OR (tenant:other’ };”
Exploit: (Educational Purposes!)
const maliciousFilter = { $or: [ { tenant: ‘attacker’ }, { tenant: { $ne: ‘attacker’ } } ] };
const results = await vectorStore.similaritySearch(‘query’, 10, maliciousFilter);
Protection: from this CVE
Upgrade to @langchain/redis 1.1.1 or later.
npm install @langchain/[email protected]
Impact:
Exposure of indexed documents outside the attacker’s intended scope. Breach of tenant isolation in multi-tenant applications built on LangChain and Redis. Potential data leaks and regulatory non-compliance.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

