CVE-2026-28277 is an unsafe deserialization vulnerability affecting LangGraph versions before 1.0.10. During checkpoint loading, msgpack-encoded data is processed using ormsgpack.unpackb with a custom extension handler capable of importing Python modules, resolving attributes, and invoking them with attacker-controlled input. An attacker who can modify persisted checkpoint data can supply a crafted payload that executes arbitrary code when the application loads it. The vulnerability can also be chained with the SQLite checkpointer SQL injection vulnerability CVE-2025-67644 to introduce an attacker-controlled checkpoint through query results without directly modifying the backing store.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unsafe deserialization in LangGraph SQLite Checkpoint versions 1.0.9 and earlier allows attackers with privileged write access to checkpoint storage to trigger unsafe Python object reconstruction through crafted checkpoint data. The plugin assigns a CVSS v3 score of 7.2 and recommends upgrading to version 1.0.10 or later. Patch information is contradictory: the description states that no known patch is public, while the solution recommends an upgrade and lists a patch publication date of July 1, 2026.
A remote code execution vulnerability in LangGraph caused by unsafe msgpack deserialization, which can be chained with injection flaws for full server compromise.
An unsafe msgpack deserialization vulnerability in LangGraph that can be chained with CVE-2025-67644 to achieve remote code execution.
An unsafe msgpack deserialization vulnerability in LangGraph's serialization logic that allows attacker-controlled MessagePack extension data to import modules and invoke arbitrary functions, enabling code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.