THREAT OPS › Threat News › [GHSA] GHSA-533j-2v4q-mw5h (high) — LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
[GHSA] GHSA-533j-2v4q-mw5h (high) — LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
GHSA-533j-2v4q-mw5h Severity: high CVE: CVE-2026-55253
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
# Executive Summary
A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods accept a filter parameter that is incorporated into Mo
Indicators of compromise
- CVE-2026-55253cve
Original source: https://github.com/advisories/GHSA-533j-2v4q-mw5h