Check Point Research disclosed three vulnerabilities in LangGraph’s persistence layer affecting self-hosted deployments that use SQLite or Redis checkpointers and expose get_state_history() with a user-controlled filter. The most severe attack chain combines a SQL injection flaw in the SQLite checkpointer, tracked as CVE-2025-67644, with unsafe msgpack deserialization, tracked as CVE-2026-28277, allowing an attacker to insert a malicious checkpoint row that is later deserialized into remote code execution. Researchers also identified a SQL injection issue in the Redis checkpointer, CVE-2026-27022, along with additional defense-in-depth SQL injection concerns in SQLite and PostgreSQL query construction.
LangChain released patches and urged users to upgrade to langgraph-checkpoint-sqlite 3.0.1 or later, langgraph 1.0.10 or later, and langgraph-checkpoint-redis 1.0.2 or later. The exposed-risk scenario described in the report applies to self-hosted environments with vulnerable checkpointer configurations, while LangSmith Deployment was reported as unaffected by the primary attack path because it uses PostgreSQL rather than the impacted SQLite or Redis setups.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
LangChain released fixes and advised users to upgrade to langgraph-checkpoint-sqlite 3.0.1 or later, langgraph 1.0.10 or later, and langgraph-checkpoint-redis 1.0.2 or later. The report also stated that LangSmith Deployment, which uses PostgreSQL, was not affected by the primary exposed-risk scenario described.
Check Point Research reported three vulnerabilities in LangGraph’s persistence layer affecting self-hosted deployments that use SQLite or Redis checkpointers when applications expose get_state_history() with a user-controlled filter. The issues included SQL injection flaws in SQLite and Redis paths and an unsafe msgpack deserialization issue that could be chained to achieve remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.