Vulnerabilities/

RediSearch Query Injection in @langchain/langgraph-checkpoint-redis

Severity:
Medium

Description

A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package’s filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping.

Recommendation

Update the @langchain/langgraph-checkpoint-redis package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@langchain/langgraph-checkpoint-redis
Anything's wrong? Let us know Last updated on February 23, 2026