# CVE-2026-55253

## Summary

- **CVE ID:** CVE-2026-55253
- **Severity:** HIGH
- **CVSS Score:** 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-943
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 14, 2026

## Description

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively rejecting keys prefixed with $. An authenticated caller who controls a filter argument through HTTP query parameters, request body fields, or agent tool arguments can inject MongoDB Query Language operators such as $regex or $where. In a multi-tenant deployment that uses the filter to enforce per-user or per-tenant isolation, injected operators can bypass intended equality filtering and expose other tenants' checkpoint or store data. Filters constructed entirely from trusted server-side values have lower practical risk. This issue is fixed in langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0.

## Affected Products

- langchain-ai — langchain-mongodb (< 0.4.0)
- langchain-ai — langgraph-checkpoint-mongodb (< 0.3.0)
- langchain-ai — langgraph-store-mongodb (< 0.4.0)

## References

- [CNA](https://github.com/langchain-ai/langchain-mongodb/security/advisories/GHSA-533j-2v4q-mw5h)
- [CNA](https://github.com/langchain-ai/langchain-mongodb/pull/384)
- [CNA](https://github.com/langchain-ai/langchain-mongodb/commit/14a6cc39e67d23fd409cd13a9caae2c329df0a09)
- [CNA](https://github.com/langchain-ai/langchain-mongodb/commit/240e7ecee432ea006d9fef6ea506bfd2e009a3f4)
- [CNA](https://github.com/langchain-ai/langchain-mongodb/commit/5465e4d3ea0ef5c88a666a6442bd853ff4bd70e5)
- [CNA](https://github.com/langchain-ai/langchain-mongodb/releases/tag/libs/langgraph-checkpoint-mongodb/v0.4.0)
- [CNA](https://github.com/langchain-ai/langchain-mongodb/releases/tag/libs/langgraph-store-mongodb/v0.3.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.39%
- **EPSS Percentile:** 32.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._