{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/langgraph-checkpoint-mongodb/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["langgraph-checkpoint-mongodb","langgraph-store-mongodb"],"_cs_severities":["high"],"_cs_tags":["nosql-injection","data-exposure","langchain","cve-2026-55253"],"_cs_type":"advisory","_cs_vendors":["LangChain"],"content_html":"\u003cp\u003eThe LangGraph MongoDB integration libraries (langgraph-checkpoint-mongodb and langgraph-store-mongodb) are vulnerable to NoSQL operator injection (CVE-2026-55253). This vulnerability stems from inadequate sanitization of the 'filter' parameter passed to the 'MongoDBSaver.list()' and 'MongoDBStore.search()' methods. Because these methods allow caller-supplied input to be embedded directly into database queries, an authenticated attacker can inject MongoDB operator keys prefixed with '$'. In multi-tenant applications where these methods are relied upon for data isolation, an attacker can manipulate the query logic to access or exfiltrate checkpoint or store data belonging to other tenants. This flaw impacts all versions of langgraph-checkpoint-mongodb prior to 0.3.0 and langgraph-store-mongodb prior to 0.4.0. Defenders should audit application code to ensure that any 'filter' parameter passed to these libraries is strictly validated and stripped of characters associated with MongoDB query operators.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in a loss of data confidentiality across tenant boundaries. Attackers can gain unauthorized read access to state, checkpoints, or stored data belonging to other users or organizations. Given the reliance on these libraries for agentic workflows and memory storage, the compromise allows for the mass exfiltration of sensitive conversational history or application state.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade 'langgraph-checkpoint-mongodb' to version 0.3.0 or later and 'langgraph-store-mongodb' to version 0.4.0 or later to patch CVE-2026-55253.\u003c/li\u003e\n\u003cli\u003eAudit application code to identify instances where user-controlled input (e.g., HTTP query parameters or request body fields) is passed directly to the 'filter' argument of 'MongoDBSaver.list()', 'MongoDBSaver.alist()', or 'MongoDBStore.search()'.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or sanitization routines on the server side to remove or escape the '$' character from any user-provided data before it is incorporated into database filter objects.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T19:15:45Z","date_published":"2026-08-20T19:15:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-langchain-mongodb-nosql-injection/","summary":"A NoSQL injection vulnerability in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries allows authenticated attackers to bypass tenant isolation boundaries and exfiltrate sensitive data via injected MongoDB query operators.","title":"NoSQL Operator Injection in LangGraph MongoDB Libraries","url":"https://feed.craftedsignal.io/briefs/2026-08-langchain-mongodb-nosql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Langgraph-Checkpoint-Mongodb","version":"https://jsonfeed.org/version/1.1"}