THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-533j-2v4q-mw5h (high) — LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

[GHSA] GHSA-533j-2v4q-mw5h (high) — LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

medgithub_advisoriesPublished 2026-08-20

GHSA-533j-2v4q-mw5h Severity: high CVE: CVE-2026-55253

LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

# Executive Summary

A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods accept a filter parameter that is incorporated into Mo

Indicators of compromise

Original source: https://github.com/advisories/GHSA-533j-2v4q-mw5h