GHSA-98xf-r82g-9mhx
MODERATECVE-2026-48121A NoSQL injection vulnerability existed in MongoDBSaver where checkpoint identifier fields from config.configurable were used in MongoDB queries without strict type enforcement. In vulnerable versions, attacker-controlled object payloads (for example MongoDB operators like $gt and $ne) could be interpreted as query operators instead of literal identifier values.
- Affected
- >=0, <1.3.1, <= 1.3.0
- Fixed in
- 1.3.1
- Weakness
- CWE-943
- Published
- 2026-06-12
- Source
- osv