Description
A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package’s filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping.
Recommendation
Update the @langchain/langgraph-checkpoint-redis package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.2
- Patched version(s): 1.0.2
References
Could your website be exposed too?
SmartScanner can check your website for RediSearch Query Injection in @langchain/langgraph-checkpoint-redis and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Payload has an SQL Injection via Query Handling - CVE-2026-34747
- OneUptime ClickHouse SQL Injection via Aggregate Query Parameters - CVE-2026-32306
- LangGraph has NoSQL parameter injection in MongoDBSaver, allowing cross-tenant state access - CVE-2026-48121
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405


