npm package report

Is @langchain/redis safe?

1 known vulnerability, worst severity LOW.

// reach

2 direct dependencies

2 carry known advisories, worst HIGH

2 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


cvss
0.0
low

severity out of 10

epss
not scored

chance of exploitation in 30 days

xyz score
not scored

CyberXYZ composite out of 10

fig. 01 — GHSA-5x6v-p487-7qh2, the advisory selected below

// 1 advisories

GHSA-5x6v-p487-7qh2

LOWCVE-2026-105799
// summary

@langchain/redis did not properly escape values used to construct structured RediSearch TAG and TEXT filters. An application that passes attacker-controlled values into these filters could allow the attacker to alter the resulting search query.

// affected versions

@langchain/redis versions through 1.1.0 are affected.

// impact

An attacker who can control values passed to the affected structured TAG or TEXT filters can inject RediSearch syntax and alter or broaden the resulting search query. In applications that use an attacker-influenceable filter as a tenant or document-access boundary, this may expose indexed documents outside the attacker's intended scope.

// remediation

Upgrade to @langchain/redis 1.1.1 or later.

The fix escapes RediSearch special characters, validates field names and structured filter types, and applies these protections across fluent filter builders and custom-schema query construction.

// credits

Thanks to @thesanjok and @shovanchakraborty for reporting this issue.

// cvss v4.0 vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Attack vector
Network
Attack complexity
Low
Attack requirements
Present
Privileges required
Low
User interaction
None
Confidentiality (vulnerable system)
Low
Integrity (vulnerable system)
None
Availability (vulnerable system)
None
Confidentiality (subsequent systems)
None
Integrity (subsequent systems)
None
Availability (subsequent systems)
None

Checked 2026-10-07 at 02:43 UTC. The most recent advisory here was published 2026-10-06. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.