GPU VulnDB

Database/AI/ML frameworks & serving

LangChain.js MongoDB chat history: unvalidated session id injects a MongoDB query condition

CVSS 6.0CVE-2026-106119AI/ML frameworks & servingcurated

Impact

MongoDBChatMessageHistory documents its session identifier as a string but does not enforce that at runtime, so a structured value supplied by an untrusted caller is interpreted as a MongoDB query condition rather than a literal. Where one shared collection holds many users' conversations, a caller able to invoke chat-history operations can read, modify, or delete another user's stored conversation - a cross-tenant read and write inside the application's own data store. This is an application-layer flaw in LLM serving glue, not a GPU or node compromise: it leaks and destroys conversation data, it does not get the attacker onto the inference host. The advisory is explicit that applications passing authenticated, server-controlled string identifiers are not affected.

Who can reach it

Any caller - authenticated at low privilege - who can reach an application endpoint that forwards a client-supplied session identifier into chat-history operations backed by a shared MongoDB collection. No access to the GPU fleet or the database itself is needed.

What to do

Upgrade @langchain/mongodb to 1.3.1 and redeploy the serving application; this is an application dependency bump and a rolling restart of the inference frontend, with no change on the GPU nodes themselves. The code-side mitigation the advisory implies works without upgrading: derive the session identifier server-side from the authenticated session, or coerce and validate it as a string before it reaches the history store.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.