LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access
- Severity:
- Medium
Description
A NoSQL injection vulnerability existed in MongoDBSaver where checkpoint identifier fields from config.configurable were used in MongoDB queries without strict type enforcement.
Recommendation
Update the @langchain/langgraph-checkpoint-mongodb package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.3.0
- Patched version(s): 1.3.1
References
Related Issues
- Feathers has a NoSQL Injection via WebSocket id Parameter in MongoDB Adapter - CVE-2026-29793
- @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution - CVE-2026-54658
- payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments) - CVE-2026-25574
- OneUptime has authorization bypass via client‑controlled is-multi-tenant-query header that leads to cross‑tenant data ex - CVE-2026-30956
You might also like:
- Tags:
- npm
- @langchain/langgraph-checkpoint-mongodb
Anything's wrong? Let us know Last updated on June 12, 2026


