CVE-2026-48121
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.7 / 10
Vulnerability Description
LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
npm
Product
@langchain/langgraph-checkpoint-mongodb
External References
- https://github.com/langchain-ai/langgraphjs/security/advisories/GHSA-98xf-r82g-9mhx
- https://github.com/langchain-ai/langgraphjs/issues/2351
- https://github.com/langchain-ai/langgraphjs/pull/2397
- https://github.com/langchain-ai/langgraphjs/commit/284226c7ca164b3c81fe2d9e32b10f1fc6b99a3c
- https://github.com/advisories/GHSA-98xf-r82g-9mhx
Discussion (0)
Add Comment
No comments yet. Be the first!