DFIR Radar[verified]@DFIR_RadarDisclosure
Check Point Research has disclosed three CVEs in LangGraph that enable SQL injection and deserialization‑based remote code execution on self‑hosted deployments, and it provides patch updates to mitigate the risks.
Jon Hill[verified]@jonhillymakesPatch
The post lists three newly disclosed CVEs in langchain-core, gives basic technical details, and notes that they have been patched in version 1.2.22.
Lucas Senechal[verified]@lucas_r_senchalDisclosure
The statement discloses a SQL injection flaw in LangGraph's SQLite checkpoints that permits manipulation of metadata filters to run arbitrary queries and access conversation histories.
TheAISignal[verified]@ainewshubliveActive Exploitation
The post reports that 7,000 Langflow servers are under active attack using CVE‑2025‑67644 (SQL injection in LangGraph's SQLite checkpointer) and CVE‑2026‑5027 (path traversal in Langflow’s file upload), which can be chained to exfiltrate OpenAI keys and CRM tokens.
Xavier Rivera[verified]@XavierRiveraXPatch
The post announces patches for CVE-2025-67644 and CVE-2026-28277, detailing an RCE chain via SQL injection and msgpack deserialization, with updated LangGraph and checkpoint‑sqlite releases provided.
NY-squared AI[verified]@NYsquaredAIPatch
Three high‑severity CVEs (CVE-2025-68664, CVE-2026-34070, CVE-2025-67644) affecting LangChain and LangGraph were announced, with immediate patch releases indicated.
Connex@Connex01Active Exploitation
The announcement highlights that CVE-2026-28277 and CVE-2025-67644 are currently being abused in real‑world attacks via path‑traversal techniques that enable malicious cron job deployment.
Asil Ozyildirim@AsilOzyildirimDisclosure
The text announces the disclosure of three CVEs affecting LangChain/LangGraph, providing their CVSS scores and types, and notes 9 million downloads that week.