CVE-2026-27022Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

@langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating user-provided filter keys and values without proper escaping. RediSearch has special syntax characters that can modify query behavior, and when user-controlled data contains these characters, the query logic can be manipulated to bypass intended access controls. This vulnerability is fixed in 1.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-20); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-20: 1Mentions · 2026-03-10: 1Mentions · 2026-06-11: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-06-11: 1Technical Details · 2026-02-20: 1Technical Details · 2026-03-10: 1Technical Details · 2026-06-11: 102-2003-1006-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-201
Disclosure1
2026-03-101
Patch1
2026-06-111
Disclosure1
Full discourse3 posts
  • DFIR Radar@DFIR_Radar
    Disclosure

    Check Point Research uncovers critical vulnerabilities in LangGraph's persistence layer allowing SQL injection to chain into remote code execution. Three CVEs impact 50M+ monthly downloads of the popular AI agent framework. Key technical details: • CVE-2025-67644: SQL injection in SQLite checkpointer via unsanitized filter keys in get_state_history() function • CVE-2026-28277: Unsafe msgpack deserialization enables RCE through custom extension handler calling importlib.import_module() • CVE-2026-27022: Same injection class affects Redis checkpointer implementation • Attack chain: Malicious filter parameter → UNION SELECT injection → fake checkpoint row → msgpack deserialization → os.system() execution Exploitation requirements: • Self-hosted LangGraph with SQLite/Redis checkpointer • Application exposes get_state_history() with user-controlled filter parameter • LangSmith managed cloud service uses PostgreSQL and is not vulnerable Impact covers teams running stateful AI agents with exposed state history endpoints. All issues patched - update to langgraph-checkpoint-sqlite 3.0.1+, langgraph 1.0.10+, and langgraph-checkpoint-redis 1.0.2+. Hunt for applications calling get_state_history() with external input and audit msgpack deserialization in AI frameworks. #DFIR_Radar

    Post summary

    Check Point Research discloses three critical CVEs in LangGraph’s persistence layer, outlining SQL injection and unsafe deserialization that enable remote code execution, and provides patch information for all affected components.

    10000183
    1.6K followersView on X
  • Mukund | Muks@CyberAmyntas
    Patch

    LangGraph users: CVE-2026-27022 affects @LangChain /langgraph-checkpoint-redis < 1.0.2. A RediSearch query injection bug can let a low-privileged user in multi-tenant deployments read other tenants’ checkpoint data, including conversation history and agent state. Upgrade to 1.0.2 now https://www.raxe.ai/labs/advisories/RAXE-2026-025 @RaxeAi

    Post summary

    CVE-2026-27022 is a RediSearch query injection flaw in langgraph‑checkpoint‑redis that lets low‑privileged users read other tenants’ checkpoint data. Updating to version 1.0.2 resolves the vulnerability.

    0000088
    1.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27022 @langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgra… https://www.cve.org/CVERecord?id=CVE-2026-27022

    Post summary

    A query injection vulnerability (CVE‑2026‑27022) affecting @langchain/langgraph‑checkpoint‑redis is identified, but no exploit, PoC, or remediation details are supplied.

    0000096
    56.4K followersView on X

Explore more