24h | 7d | 30d

Overview

  • langchain-ai
  • langgraph

10 Dec 2025
Published
11 Dec 2025
Updated

CVSS v3.1
HIGH (7.3)
EPSS
0.02%

KEV

Description

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metadata filter keys, affecting applications that accept untrusted metadata filter keys (not just filter values) in checkpoint search operations. The _metadata_predicate() function constructs SQL queries by interpolating filter keys directly into f-strings without validation. This issue is fixed in version 3.0.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 12 hours ago

Bluesky

Profile picture fallback
~Checkpoint~ Check Point Research found SQLi and unsafe deserialization flaws in LangGraph checkpointers leading to RCE. - IOCs: CVE-2025-67644, CVE-2026-28277, CVE-2026-27022 - #CVE202567644 #LangGraph #ThreatIntel
  • 1
  • 0
  • 0
  • 12h ago

Overview

  • langchain-ai
  • langgraph

05 Mar 2026
Published
06 Mar 2026
Updated

CVSS v3.1
MEDIUM (6.8)
EPSS
0.33%

KEV

Description

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that triggers unsafe object reconstruction when the checkpoint is loaded. No known patch is public.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 12 hours ago

Bluesky

Profile picture fallback
~Checkpoint~ Check Point Research found SQLi and unsafe deserialization flaws in LangGraph checkpointers leading to RCE. - IOCs: CVE-2025-67644, CVE-2026-28277, CVE-2026-27022 - #CVE202567644 #LangGraph #ThreatIntel
  • 1
  • 0
  • 0
  • 12h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture fallback
~Cisa~ Multiple critical flaws in Naxclow IoT Platform allow device takeover, credential harvesting, and communication interception. - IOCs: CVE-2026-42947, CVE-2026-50108, CVE-2026-28742 - #CVE202642947 #IoT #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture fallback
~Cisa~ Multiple critical flaws in Naxclow IoT Platform allow device takeover, credential harvesting, and communication interception. - IOCs: CVE-2026-42947, CVE-2026-50108, CVE-2026-28742 - #CVE202642947 #IoT #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture fallback
~Cisa~ Multiple critical flaws in Naxclow IoT Platform allow device takeover, credential harvesting, and communication interception. - IOCs: CVE-2026-42947, CVE-2026-50108, CVE-2026-28742 - #CVE202642947 #IoT #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago
Showing 51 to 55 of 55 CVEs