Database/AI/ML frameworks & serving
LangChain.js MongoDB chat history: unvalidated session id injects a MongoDB query condition
Impact
MongoDBChatMessageHistory documents its session identifier as a string but does not enforce that at runtime, so a structured value supplied by an untrusted caller is interpreted as a MongoDB query condition rather than a literal. Where one shared collection holds many users' conversations, a caller able to invoke chat-history operations can read, modify, or delete another user's stored conversation - a cross-tenant read and write inside the application's own data store. This is an application-layer flaw in LLM serving glue, not a GPU or node compromise: it leaks and destroys conversation data, it does not get the attacker onto the inference host. The advisory is explicit that applications passing authenticated, server-controlled string identifiers are not affected.
Who can reach it
Any caller - authenticated at low privilege - who can reach an application endpoint that forwards a client-supplied session identifier into chat-history operations backed by a shared MongoDB collection. No access to the GPU fleet or the database itself is needed.
What to do
Upgrade @langchain/mongodb to 1.3.1 and redeploy the serving application; this is an application dependency bump and a rolling restart of the inference frontend, with no change on the GPU nodes themselves. The code-side mitigation the advisory implies works without upgrading: derive the session identifier server-side from the authenticated session, or coerce and validate it as a string before it reaches the history store.
References
Related entries
- JupyterLab: authenticated users bypass administrator plugin lock rules via /lab/api/pluginsCVE-2026-73627 · JupyterLab Extension/Plugin Manager (/lab/api/plugins lock-rule enforcement)Medium
- vLLM: arbitrary HTTP method tokens create unbounded Prometheus label sets and exhaust the serviceCVE-2026-105759 · vLLM Rust frontend track_http_metrics middleware (Prometheus label cardinality)Medium
- Ray (dashboard DELETE endpoints): Browser-origin protection covers POST/PUT but not DELETECVE-2026-27482 · Ray (dashboard DELETE endpoints)Medium
- LocalAI (`/models/apply`): SSRF and partial local file inclusionCVE-2024-6095 · LocalAI (`/models/apply`)Medium
- NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tamperingCVE-2026-65087 · NVIDIA NemoClaw (credential storage)Medium
- Linux perf/x86/amd/uncore - memory leak in the events array: Per-CPU northbridge and last-level-cache uncore contextsCVE-2022-49784 · Linux perf/x86/amd/uncore - memory leak in the events arrayMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.