{"id":"CVE-2026-27022","aliases":["GHSA-5mx2-w598-339m"],"url":"https://o3.security/vulnerability/CVE-2026-27022","summary":"RediSearch Query Injection in @langchain/langgraph-checkpoint-redis","details":"@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.","published":"2026-02-20T21:06:53.773Z","modified":"2026-08-07T11:50:50.406048660Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@langchain/langgraph-checkpoint-redis","fixedVersion":"1.0.2"}],"fix":{"url":"https://github.com/langchain-ai/langgraphjs/commit/814c76dc3938d0f6f7e17ca3bc11d6a12270b2a1","label":"langchain-ai/langgraphjs@814c76d"},"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraphjs/releases/tag/@langchain/langgraph-checkpoint-redis@1.0.2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27022.json"},{"type":"ADVISORY","url":"https://github.com/langchain-ai/langgraphjs/security/advisories/GHSA-5mx2-w598-339m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27022"},{"type":"FIX","url":"https://github.com/langchain-ai/langgraphjs/commit/814c76dc3938d0f6f7e17ca3bc11d6a12270b2a1"},{"type":"FIX","url":"https://github.com/langchain-ai/langgraphjs/pull/1943"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:50:50.406048660Z"}}