CVE-2026-28277Patch(langchain / langgraph)

MEDIUMCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch langchain langgraph systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that triggers unsafe object reconstruction when the checkpoint is loaded. No known patch is public.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langgraph

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-05); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
langgraph

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-05: 1Mentions · 2026-06-11: 1Mentions · 2026-06-12: 1Mentions · 2026-06-20: 1Active Exploitation · 2026-06-20: 1Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-03-05: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-20: 103-0506-1106-1206-20
Signal classification3 categories
Patch
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-051
General1
2026-06-111
Patch1
2026-06-121
Patch1
2026-06-201
Active Exploitation1
Full discourse4 posts
  • Connex@Connex01
    Active Exploitation

    4/ • The Impact: Attackers use simple ../ sequences to bypass constraints and drop malicious cron jobs straight onto the host. Active in-the-wild exploitation is happening right now. 2. LangGraph Memory Injection (CVE-2026-28277 / CVE-2025-67644)**

    Post summary

    The text confirms that CVE-2026-28277 and CVE-2025-67644 are currently being exploited in the wild through simple directory traversal attacks that deploy cron jobs, with no PoC or patch information provided.

    1000042
    102 followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Check Point Research uncovers critical vulnerabilities in LangGraph's persistence layer allowing SQL injection to chain into remote code execution. Three CVEs impact 50M+ monthly downloads of the popular AI agent framework. Key technical details: • CVE-2025-67644: SQL injection in SQLite checkpointer via unsanitized filter keys in get_state_history() function • CVE-2026-28277: Unsafe msgpack deserialization enables RCE through custom extension handler calling importlib.import_module() • CVE-2026-27022: Same injection class affects Redis checkpointer implementation • Attack chain: Malicious filter parameter → UNION SELECT injection → fake checkpoint row → msgpack deserialization → os.system() execution Exploitation requirements: • Self-hosted LangGraph with SQLite/Redis checkpointer • Application exposes get_state_history() with user-controlled filter parameter • LangSmith managed cloud service uses PostgreSQL and is not vulnerable Impact covers teams running stateful AI agents with exposed state history endpoints. All issues patched - update to langgraph-checkpoint-sqlite 3.0.1+, langgraph 1.0.10+, and langgraph-checkpoint-redis 1.0.2+. Hunt for applications calling get_state_history() with external input and audit msgpack deserialization in AI frameworks. #DFIR_Radar

    Post summary

    Check Point Research disclosed three CVEs in LangGraph, detailed the vulnerability mechanics, and provided specific patch versions to remedy the issues.

    10000183
    1.6K followersView on X
  • Xavier Rivera@XavierRiveraX
    Patch

    Three patched LangGraph flaws include an RCE chain: SQL injection in the SQLite checkpointer (CVE-2025-67644) chains with msgpack deserialization (CVE-2026-28277) to execute code. Managed LangSmith unaffected. Update: langgraph 1.0.10, checkpoint-sqlite 3.0.1.

    Post summary

    The post announces that three LangGraph vulnerabilities—SQL injection and msgpack deserialization exploitable for RCE—have been patched, and it lists the updated package versions.

    0000060
    571 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28277 LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, La… https://www.cve.org/CVERecord?id=CVE-2026-28277

    Post summary

    The text references CVE-2026-28277 and briefly describes the affected component and version but offers no further details or actionable information.

    0000081
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlanggraph---

Explore more