Tag
high
advisory
NoSQL Operator Injection in LangGraph MongoDB Libraries
2 TTPsA NoSQL injection vulnerability in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries allows authenticated attackers to bypass tenant isolation boundaries and exfiltrate sensitive data via injected MongoDB query operators.
langgraph-checkpoint-mongodb +1
nosql-injection
data-exposure
langchain
cve-2026-55253
2t
high
advisory
LangChain Core Path Traversal Vulnerability in Legacy APIs
1 rule 1 TTPA path traversal vulnerability in LangChain Core's legacy `load_prompt` functions allows attackers to read arbitrary files by injecting malicious paths into prompt configurations.
langchain
path-traversal
vulnerability
1r
1t
high
advisory
LangChain Unsafe Deserialization Vulnerability
2 rules 1 TTPLangChain is vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists, potentially leading to persistent chat-history poisoning, prompt injection, credential disclosure, or server-side requests.
langchain-core
langchain
deserialization
vulnerability
2r
1t