<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 05:51:25 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-270443</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-270443</link>
      <description>EUVD-2026-270443</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-270443</guid>
    </item>
    <item>
      <title>fkie_cve-2026-27022</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27022</link>
      <description>&lt;p&gt;@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package&amp;#39;s filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package&amp;#39;s filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-27022</guid>
    </item>
    <item>
      <title>GHSA-5mx2-w598-339m — RediSearch Query Injection in @langchain/langgraph-checkpoint-redis</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mx2-w598-339m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @langchain/langgraph-checkpoint-redis&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A query injection vulnerability exists in the `@langchain/langgraph-checkpoint-redis` package&amp;#39;s filter handling. The `RedisSaver` and `ShallowRedisSaver` classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls.&lt;/p&gt;
&lt;p&gt;## Attack surface&lt;/p&gt;
&lt;p&gt;The core vulnerability was in the `list()` methods of both `RedisSaver` and `ShallowRedisSaver`: these methods failed to escape RediSearch special characters in filter keys and values when constructing queries. When unescaped data containing RediSearch syntax was used, the injected operators were interpreted by RediSearch rather than treated as literal search values.&lt;/p&gt;
&lt;p&gt;This escaping bug enabled the following attack vector:&lt;/p&gt;
&lt;p&gt;- **Thread boundary escape via OR operator**: RediSearch uses `|` as an OR operator with specific precedence rules. A query like `A B | C` is interpreted as `(A AND B) OR C`. By injecting `}) | (@thread_id:{*` into a filter value, an attacker can append an OR clause that matches all threads, effectively bypassing the thread isolation constraint.&lt;/p&gt;
&lt;p&gt;The injected query `(@thread_id:{legitimate-thread}) (@source:{x}) | (@thread_id:{*})` matches:&lt;/p&gt;
&lt;p&gt;- Documents with `thread_id:legitimate-thread AND source:x`, OR
- Documents with ANY `thread_id`&lt;/p&gt;
&lt;p&gt;The second claus…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @langchain/langgraph-checkpoint-redis&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A query injection vulnerability exists in the `@langchain/langgraph-checkpoint-redis` package&amp;#39;s filter handling. The `RedisSaver` and `ShallowRedisSaver` classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls.&lt;/p&gt;
&lt;p&gt;## Attack surface&lt;/p&gt;
&lt;p&gt;The core vulnerability was in the `list()` methods of both `RedisSaver` and `ShallowRedisSaver`: these methods failed to escape RediSearch special characters in filter keys and values when constructing queries. When unescaped data containing RediSearch syntax was used, the injected operators were interpreted by RediSearch rather than treated as literal search values.&lt;/p&gt;
&lt;p&gt;This escaping bug enabled the following attack vector:&lt;/p&gt;
&lt;p&gt;- **Thread boundary escape via OR operator**: RediSearch uses `|` as an OR operator with specific precedence rules. A query like `A B | C` is interpreted as `(A AND B) OR C`. By injecting `}) | (@thread_id:{*` into a filter value, an attacker can append an OR clause that matches all threads, effectively bypassing the thread isolation constraint.&lt;/p&gt;
&lt;p&gt;The injected query `(@thread_id:{legitimate-thread}) (@source:{x}) | (@thread_id:{*})` matches:&lt;/p&gt;
&lt;p&gt;- Documents with `thread_id:legitimate-thread AND source:x`, OR
- Documents with ANY `thread_id`&lt;/p&gt;
&lt;p&gt;The second claus…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mx2-w598-339m</guid>
    </item>
  </channel>
</rss>
