pypi package report

Is langgraph-store-mongodb safe?

1 known vulnerability, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      No published models are known to use this package.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 42nd percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-533j-2v4q-mw5h, the advisory selected below

      // 1 advisories

      GHSA-533j-2v4q-mw5h

      HIGHCVE-2026-55253
      // executive summary

      A NoSQL injection issue exists in the langgraph-checkpoint-mongodb and langgraph-store-mongodb libraries. MongoDBSaver.list() and MongoDBStore.search() methods accept a filter parameter that is incorporated into MongoDB queries without sufficient validation. Because MongoDB query operator keys (those prefixed with $) are not rejected during filter construction, a caller with control of the filter input can embed MongoDB query operators directly into the query.

      ---

      // cvss 4.0

      | Field | Value | |---|---| | CVSS Version | 4.0 | | Vector String | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N | | Base Score | 7.1 (High) |

      | Metric | Value | Rationale | |---|---|---| | Attack Vector (AV) | Network | Triggerable remotely via API | | Attack Complexity (AC) | Low | No special conditions required | | Attack Requirements (AT) | None | No prerequisite deployment or execution conditions | | Privileges Required (PR) | Low | Authenticated caller of the checkpoint/store API | | User Interaction (UI) | None | No user action required | | Vulnerable System Confidentiality (VC) | None | No direct impact on the vulnerable component itself | | Vulnerable System Integrity (VI) | None | Read-only access | | Vulnerable System Availability (VA) | None | No service disruption | | Subsequent System Confidentiality (SC) | High | Full access to other tenants' checkpoint data | | Subsequent System Integrity (SI) | None | No write or modification capability | | Subsequent System Availability (SA) | None | No service disruption to downstream systems |

      // cvss 3.1

      | Field | Value | |---|---| | CVSS Version | 3.1 | | Vector String | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N | | Base Score | 7.7 (High) |

      | Metric | Value | Rationale | |---|---|---| | Attack Vector | Network | Triggerable remotely via API | | Attack Complexity | Low | No special conditions required | | Privileges Required | Low | Authenticated caller of the checkpoint/store API | | User Interaction | None | No user action required | | Scope | Changed | Impact crosses tenant boundaries | | Confidentiality | High | Full access to other tenants' checkpoint data | | Integrity | None | Read-only access | | Availability | None | No service disruption | ---

      // affected packages

      | Package | Distribution | Affected Methods | Affected Versions | |---|---|---|---| | langgraph-checkpoint-mongodb | PyPI | MongoDBSaver.list(), MongoDBSaver.alist() | < 0.3.0 | | langgraph-store-mongodb | PyPI | MongoDBStore.search() | < 0.4.0 | ---

      // how do i know if i am affected?

      You are likely affected if all of the following are true:

      • Your application uses langgraph-checkpoint-mongodb or langgraph-store-mongodb.
      • Your application calls MongoDBSaver.list(), MongoDBSaver.alist(), or

      MongoDBStore.search() with a filter argument.

      • Any part of that filter argument is derived from user-controlled input — for example, HTTP

      query parameters, request body fields, or agent tool arguments.

      • You operate in a multi-tenant context where the filter is used to enforce per-user or

      per-tenant data isolation.

      If the filter argument is constructed entirely from trusted, server-side values, the practical risk is lower, but upgrading is still recommended.

      // how do i fix the issue?

      Upgrade to the version of langgraph-checkpoint-mongodb and langgraph-store-mongodb. If you cannot upgrade immediately, apply the following mitigation: in your application code, before passing any user-controlled input to the filter parameter, remove or escape MongoDB Query metacharacters such as “$”.

      ---

      // acknowledgements

      Thanks to Kenichi Kawaguchi for responsibly disclosing this issue via the GitHub Security Advisory program on the langchain-mongodb repository.

      ---

      // revisions

      | Date | Description | |---|---| | 2026-06-05 | Initial advisory published |

      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      Low
      User interaction
      None
      Scope
      Changed
      Confidentiality
      High
      Integrity
      None
      Availability
      None

      Checked 2026-09-26 at 01:03 UTC. The most recent advisory here was published 2026-08-20. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.