CVE-2026-48121 is a NoSQL parameter injection vulnerability in LangGraph MongoDBSaver affecting @langchain/langgraph-checkpoint-mongodb prior to 1.3.1. The issue arises when attacker-controlled values supplied in config.configurable for checkpoint identifier fields such as thread_id, checkpoint_ns, or checkpoint_id are used in MongoDB query and write paths without sufficient runtime validation. By injecting MongoDB operators into these identifier fields, an attacker can alter query semantics and bypass intended thread or tenant scoping for checkpoint retrieval.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a functional, localhost-only classroom proof of concept for GHSA-98xf-r82g-9mhx affecting LangGraph's MongoDBSaver package version 1.3.0. The repository contains a Node.js HTTP server, a browser UI, Docker Compose configuration for MongoDB 8.0.13, LangGraph fixture/graph code, and integration tests. It installs vulnerable and patched MongoDBSaver releases side by side through npm aliases and seeds isolated demo_vulnerable and demo_patched databases with fictional Alice and Bob conversations. The primary exploit logic is in src/fixture.js, which supplies thread_id as {"$gt":""}; src/demo.js invokes the real LangGraph restore path; and src/saver.js captures the actual MongoDB find command. Under v1.3.0, the injected operator reaches the checkpoints query and causes Bob's newest checkpoint, including the fictional private note, to be restored. Under v1.3.1, type validation rejects the object before any lookup. Writes are deliberately suppressed during trials to preserve a repeatable fixture, but the vulnerable read path is real and unmodified. The server and MongoDB are explicitly bound to 127.0.0.1, no external targets or credentials are present, and the deterministic graph does not call an LLM.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.