CVE-2026-55253
HIGHCVE-2026-55253 is a high-severity (CVSS 7.7) vulnerability in langgraph-checkpoint-mongodb. O3 Security confirms whether CVE-2026-55253 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
Real-World Exposure
langgraph-checkpoint-mongodb🐍langgraph-store-mongodbReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Executive Summary
A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods accept a filter parameter that is incorporated into MongoDB queries without sufficient validation. Because MongoDB query operator keys (those prefixed with $) are not rejected during filter construction, a caller with control of the filter input can embed MongoDB query operators directly into the query.
CVSS Details
CVSS 4.0
| Field | Value |
|---|---|
| CVSS Version | 4.0 |
| Vector String | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| Base Score | 7.1 (High) |
| Metric | Value | Rationale |
|---|---|---|
| Attack Vector (AV) | Network | Triggerable remotely via API |
| Attack Complexity (AC) | Low | No special conditions required |
| Attack Requirements (AT) | None | No prerequisite deployment or execution conditions |
| Privileges Required (PR) | Low | Authenticated caller of the checkpoint/store API |
| User Interaction (UI) | None | No user action required |
| Vulnerable System Confidentiality (VC) | None | No direct impact on the vulnerable component itself |
| Vulnerable System Integrity (VI) | None | Read-only access |
| Vulnerable System Availability (VA) | None | No service disruption |
| Subsequent System Confidentiality (SC) | High | Full access to other tenants' checkpoint data |
| Subsequent System Integrity (SI) | None | No write or modification capability |
| Subsequent System Availability (SA) | None | No service disruption to downstream systems |
CVSS 3.1
| Field | Value |
|---|---|
| CVSS Version | 3.1 |
| Vector String | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| Base Score | 7.7 (High) |
| Metric | Value | Rationale |
|---|---|---|
| Attack Vector | Network | Triggerable remotely via API |
| Attack Complexity | Low | No special conditions required |
| Privileges Required | Low | Authenticated caller of the checkpoint/store API |
| User Interaction | None | No user action required |
| Scope | Changed | Impact crosses tenant boundaries |
| Confidentiality | High | Full access to other tenants' checkpoint data |
| Integrity | None | Read-only access |
| Availability | None | No service disruption |
Affected Packages
| Package | Distribution | Affected Methods | Affected Versions |
|---|---|---|---|
langgraph-checkpoint-mongodb | PyPI | MongoDBSaver.list(), MongoDBSaver.alist() | < 0.3.0 |
langgraph-store-mongodb | PyPI | MongoDBStore.search() | < 0.4.0 |
Advisory FAQ
How do I know if I am affected?
You are likely affected if all of the following are true:
- Your application uses
langgraph-checkpoint-mongodborlanggraph-store-mongodb. - Your application calls
MongoDBSaver.list(),MongoDBSaver.alist(), orMongoDBStore.search()with afilterargument. - Any part of that
filterargument is derived from user-controlled input — for example, HTTP query parameters, request body fields, or agent tool arguments. - You operate in a multi-tenant context where the
filteris used to enforce per-user or per-tenant data isolation.
If the filter argument is constructed entirely from trusted, server-side values, the practical risk is
lower, but upgrading is still recommended.
How do I fix the issue?
Upgrade to the version of langgraph-checkpoint-mongodb and langgraph-store-mongodb.
If you cannot upgrade immediately, apply the following mitigation: in your application code,
before passing any user-controlled input to the filter parameter, remove or escape MongoDB
Query metacharacters such as “$”.
Acknowledgements
Thanks to Kenichi Kawaguchi for responsibly disclosing this issue via the GitHub Security Advisory program on the langchain-mongodb repository.
Revisions
| Date | Description |
|---|---|
| 2026-06-05 | Initial advisory published |
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | langgraph-checkpoint-mongodb | all versions | 0.3.0 |
| 🐍PyPI | langgraph-store-mongodb | all versions | 0.4.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for langgraph-checkpoint-mongodb. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update langgraph-checkpoint-mongodb to 0.3.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-55253 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether CVE-2026-55253 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to CVE-2026-55253. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is CVE-2026-55253 in your dependencies?
O3 detects CVE-2026-55253 across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.