
Check Point Research uncovers critical vulnerabilities in LangGraph's persistence layer allowing SQL injection to chain into remote code execution. Three CVEs impact 50M+ monthly downloads of the popular AI agent framework. Key technical details: • CVE-2025-67644: SQL injection in SQLite checkpointer via unsanitized filter keys in get_state_history() function • CVE-2026-28277: Unsafe msgpack deserialization enables RCE through custom extension handler calling importlib.import_module() • CVE-2026-27022: Same injection class affects Redis checkpointer implementation • Attack chain: Malicious filter parameter → UNION SELECT injection → fake checkpoint row → msgpack deserialization → os.system() execution Exploitation requirements: • Self-hosted LangGraph with SQLite/Redis checkpointer • Application exposes get_state_history() with user-controlled filter parameter • LangSmith managed cloud service uses PostgreSQL and is not vulnerable Impact covers teams running stateful AI agents with exposed state history endpoints. All issues patched - update to langgraph-checkpoint-sqlite 3.0.1+, langgraph 1.0.10+, and langgraph-checkpoint-redis 1.0.2+. Hunt for applications calling get_state_history() with external input and audit msgpack deserialization in AI frameworks. #DFIR_Radar
Post summary
Check Point Research discloses three critical CVEs in LangGraph’s persistence layer, outlining SQL injection and unsafe deserialization that enable remote code execution, and provides patch information for all affected components.


