A vulnerability marked as critical has been reported in langchain-ai langgraphjs up to 1.3.0. This affects the function
MongoDBSaver.getTuple of the component CheckpointSaver. Performing a manipulation of the argument configurable results in improper neutralization of special elements in data query logic.
This vulnerability was named CVE-2026-48121. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.