TheZDIBugs@TheZDIBugsDisclosure
An advisory discloses CVE-2026-27794, a remote code execution vulnerability in LangChain LangGraph BaseCache caused by deserialization of untrusted data, with a CVSS score of 8.1.
cvereports@_cvereportsDisclosure
LangGraph’s caching layer uses Python’s insecure `pickle` module, creating a critical deserialization flaw that can lead to remote code execution. The report highlights the vulnerability but does not provide PoC, exploit code, or patch details.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE-2026-27794, a remote code execution vulnerability in LangGraph before v4.0.0, without providing PoC, exploit, or patch details.
CVE@CVEnewDisclosure
The text announces a Remote Code Execution vulnerability in LangGraph Checkpoint prior to version 4.0.0, providing only the vulnerability type and a link to the CVE record, with no PoC, exploit, or patch details.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new CVE (CVE-2026-27794) has been disclosed, indicating a remote code execution vulnerability in LangGraph Checkpoint due to unsafe pickle deserialization.