<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T03:57:31.399517+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-383616</id>
    <title>EUVD-2026-383616</title>
    <updated>2026-10-10T03:57:31.401729+00:00</updated>
    <content>EUVD-2026-383616</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-383616"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-106119</id>
    <title>fkie_cve-2026-106119</title>
    <updated>2026-10-10T03:57:31.401765+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not enforce the documented string type for an untrusted structured session identifier at runtime, allowing the identifier to be interpreted as a MongoDB query condition rather than as a literal value when multiple users' histories are stored in a shared MongoDB collection. An attacker able to invoke chat-history operations can read, modify, or delete another user's stored conversation. Applications using authenticated, server-controlled string identifiers are not affected. This issue is fixed in version 1.3.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-106119"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m6rx-h84q-8r95</id>
    <title>GHSA-m6rx-h84q-8r95 — LangChain: MongoDBChatMessageHistory query injection can allow cross-session access</title>
    <updated>2026-10-10T03:57:31.401800+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @langchain/mongodb</p>
<p>## Impact</p>
<p>`MongoDBChatMessageHistory` did not enforce the documented string type for session identifiers at runtime. In affected applications, a structured session identifier could be interpreted as a MongoDB query condition rather than as a literal identifier.</p>
<p>Applications are affected when they pass untrusted session identifier input to `MongoDBChatMessageHistory` and store multiple users’ histories in the same collection. An attacker who can invoke chat-history operations may be able to read, modify, or delete another user’s stored conversation.</p>
<p>Applications that derive the session identifier from an authenticated, server-controlled value and enforce its type are not affected by this path.</p>
<p>## Patches</p>
<p>The issue is fixed in `@langchain/mongodb` version **1.3.1**.</p>
<p>Users of affected versions should upgrade to version 1.3.1 or later. The patched version validates session identifiers at runtime and ensures they are compared as literal values in MongoDB queries.</p>
<p>## Workarounds</p>
<p>If an immediate upgrade is not possible, applications must reject session identifiers that are not non-empty strings. Session identifiers should be derived from an authenticated, server-controlled value and must not be passed directly from an untrusted request field.</p>
<p>Upgrading remains the recommended remediation.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m6rx-h84q-8r95"/>
  </entry>
</feed>
