CVE-2025-67644Patch(langchain / langgraph-checkpoint-sqlite)

MEDIUMCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch langchain langgraph-checkpoint-sqlite systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metadata filter keys, affecting applications that accept untrusted metadata filter keys (not just filter values) in checkpoint search operations. The _metadata_predicate() function constructs SQL queries by interpolating filter keys directly into f-strings without validation. This issue is fixed in version 3.0.1.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langgraph-checkpoint-sqlite

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • Peaked 8d ago at 1 mentions (2026-03-28); latest day: 1
  • 9 total mentions across 9 days

Affected systems

Vendors
Products
langgraph-checkpoint-sqlite

Deep dive

Activity timeline9 mentions / 9d
00111Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-04-04: 1Mentions · 2026-04-17: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-20: 1Mentions · 2026-06-22: 1Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-17: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-22: 103-2803-3003-3104-0404-1706-1106-1206-2006-22
Signal classification3 categories
Patch
444.4%
Disclosure
333.3%
Active Exploitation
222.2%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-301
Patch1
2026-03-311
Patch1
2026-04-041
Patch1
2026-04-171
Disclosure1
2026-06-111
Disclosure1
2026-06-121
Patch1
2026-06-201
Active Exploitation1
2026-06-221
Active Exploitation1
Full discourse9 posts
  • Connex@Connex01
    Active Exploitation

    4/ • The Impact: Attackers use simple ../ sequences to bypass constraints and drop malicious cron jobs straight onto the host. Active in-the-wild exploitation is happening right now. 2. LangGraph Memory Injection (CVE-2026-28277 / CVE-2025-67644)**

    Post summary

    The announcement highlights that CVE-2026-28277 and CVE-2025-67644 are currently being abused in real‑world attacks via path‑traversal techniques that enable malicious cron job deployment.

    1000042
    102 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Check Point Research uncovers critical vulnerabilities in LangGraph's persistence layer allowing SQL injection to chain into remote code execution. Three CVEs impact 50M+ monthly downloads of the popular AI agent framework. Key technical details: • CVE-2025-67644: SQL injection in SQLite checkpointer via unsanitized filter keys in get_state_history() function • CVE-2026-28277: Unsafe msgpack deserialization enables RCE through custom extension handler calling importlib.import_module() • CVE-2026-27022: Same injection class affects Redis checkpointer implementation • Attack chain: Malicious filter parameter → UNION SELECT injection → fake checkpoint row → msgpack deserialization → os.system() execution Exploitation requirements: • Self-hosted LangGraph with SQLite/Redis checkpointer • Application exposes get_state_history() with user-controlled filter parameter • LangSmith managed cloud service uses PostgreSQL and is not vulnerable Impact covers teams running stateful AI agents with exposed state history endpoints. All issues patched - update to langgraph-checkpoint-sqlite 3.0.1+, langgraph 1.0.10+, and langgraph-checkpoint-redis 1.0.2+. Hunt for applications calling get_state_history() with external input and audit msgpack deserialization in AI frameworks. #DFIR_Radar

    Post summary

    Check Point Research has disclosed three CVEs in LangGraph that enable SQL injection and deserialization‑based remote code execution on self‑hosted deployments, and it provides patch updates to mitigate the risks.

    10000183
    1.6K followersView on X
  • Asil Ozyildirim@AsilOzyildirim
    Disclosure

    March 2026: Three vulns in LangChain/LangGraph disclosed. CVE-2026-34070 (7.5): Arbitrary file access CVE-2025-68664 (9.3): API key leakage CVE-2025-67644 (7.3): SQL injection 9 million LangGraph downloads that week. How many organizations realized their agents compromised?

    Post summary

    The text announces the disclosure of three CVEs affecting LangChain/LangGraph, providing their CVSS scores and types, and notes 9 million downloads that week.

    10000491
    3 followersView on X
  • Jon Hill@jonhillymakes
    Patch

    The 3 CVEs: - CVE-2026-34070: Path Traversal (CVSS 7.5) - reads your filesystem - CVE-2025-68664: Deserialization Injection (CVSS 9.3 Critical) - RCE on your server - CVE-2025-67644: SQL Injection (CVSS 7.3) - exposes conversation history Patched in langchain-core 1.2.22.

    Post summary

    The post lists three newly disclosed CVEs in langchain-core, gives basic technical details, and notes that they have been patched in version 1.2.22.

    10000169
    818 followersView on X
  • bigmacd@bigmacd16684
    Patch

    Patches released for LangGraph SQLite checkpoint (CVE-2025-67644, CVSS 7.3) fixing SQL injection & exposing conversation histories due to env secrets. Update to langchain-core ≥1.2.22, langchain-core 0.3.81/1.2.5, langgraph to secure. #

    Post summary

    Patches have been released for CVE‑2025‑67644 to fix an SQL injection vulnerability in LangGraph SQLite checkpoint, with recommended updates to langchain‑core and langgraph versions.

    10000249
    6 followersView on X
  • Lucas Senechal@lucas_r_senchal
    Disclosure

    CVE-2025-67644: SQL injection in LangGraph's SQLite checkpoints. Manipulate metadata filter keys, run arbitrary queries, access conversation histories.

    Post summary

    The statement discloses a SQL injection flaw in LangGraph's SQLite checkpoints that permits manipulation of metadata filters to run arbitrary queries and access conversation histories.

    10000202
    192 followersView on X
  • TheAISignal@ainewshublive
    Active Exploitation

    7,000 Langflow servers are under active attack — and LangGraph + LangChain have the same holes. CVE-2025-67644: SQL injection in LangGraph's SQLite checkpointer (CVSS 7.3) CVE-2026-5027: path traversal in Langflow's file upload (CVSS 8.8) These can be chained to leak OpenAI keys + CRM tokens. Urgent read 👇 http://ainewshub.live/article/7000-langflow-servers-are-under-attack-langgraph-and-langchain-have-the-same-hol #LLM #Agents

    Post summary

    The post reports that 7,000 Langflow servers are under active attack using CVE‑2025‑67644 (SQL injection in LangGraph's SQLite checkpointer) and CVE‑2026‑5027 (path traversal in Langflow’s file upload), which can be chained to exfiltrate OpenAI keys and CRM tokens.

    0000086
    12 followersView on X
  • Xavier Rivera@XavierRiveraX
    Patch

    Three patched LangGraph flaws include an RCE chain: SQL injection in the SQLite checkpointer (CVE-2025-67644) chains with msgpack deserialization (CVE-2026-28277) to execute code. Managed LangSmith unaffected. Update: langgraph 1.0.10, checkpoint-sqlite 3.0.1.

    Post summary

    The post announces patches for CVE-2025-67644 and CVE-2026-28277, detailing an RCE chain via SQL injection and msgpack deserialization, with updated LangGraph and checkpoint‑sqlite releases provided.

    0000060
    571 followersView on X
  • NY-squared AI@NYsquaredAI
    Patch

    3 serious CVEs just dropped for LangChain + LangGraph: - CVE-2025-68664 (CVSS 9.3): API keys & env secrets leak via unsafe deserialization - CVE-2026-34070 (CVSS 7.5): Path traversal -- arbitrary file read - CVE-2025-67644 (CVSS 7.3): SQL injection into conversation history 60M downloads/week. The core of your AI stack is now an attack surface. Patch now: v1.2.22+ / v0.3.81+ / langgraph-checkpoint-sqlite v3.0.1+ #AISecurity #LangChain #LLMSecurity

    Post summary

    Three high‑severity CVEs (CVE-2025-68664, CVE-2026-34070, CVE-2025-67644) affecting LangChain and LangGraph were announced, with immediate patch releases indicated.

    00000415
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlanggraph-checkpoint-sqlite-python-

Explore more