What is CVE-2026-48121?
CVE-2026-48121 is a NoSQL injection vulnerability in the @langchain/langgraph-checkpoint-mongodb package. Versions 1.3.0 and below are affected, where checkpoint identifiers from `config.configurable` are passed unsanitized into MongoDB queries. Immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-48121 @langchain/langgraph-checkpoint-mongodb paketində NoSQL injection zəifliyidir. 1.3.0 və aşağı versiyalar təsirlənir, burada `config.configurable` vasitəsilə ötürülən checkpoint identifikatorları MongoDB sorğularına birbaşa daxil edilir. Dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of @langchain/langgraph-checkpoint-mongodb are affected by CVE-2026-48121?
Versions 1.3.0 and below are affected.
What is the cause of CVE-2026-48121?
The vulnerability is caused by checkpoint identifiers from `config.configurable` being passed unsanitized into MongoDB queries.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.