CVE-2025-67644
CVSS 7.3 HIGH: langGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). EPSS 2% (82º percentile).
Vulnerabilità ed exploit
Le distribuzioni LangGraph self-hosted possono essere spinte dalla ricerca dello stato all’esecuzione di codice attraverso lo store dei checkpoint. La rottura non è il loop di reasoning dell’agente. È il layer di persistenza che ricarica la cronologia memorizzata come oggetti fidati, quindi un checkpoint malevolo può diventare input eseguibile.
2 fonti · 12 giu
CVSS 7.3 HIGH: langGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). EPSS 2% (82º percentile).
CVSS 6.8 MEDIUM: langGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). EPSS 0.6% (47º percentile).
The Hacker News
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Three patched LangGraph flaws could let attackers chain SQL injection and unsafe deserialization for RCE in self-hosted deployments.
originaleCheck Point Research
From SQLi to RCE - Exploiting LangGraph’s Checkpointer - Check Point Research
Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state.
originalePart of the PlainSec briefing for 2026-06-12
Every edition of this story: I Checkpoint di LangGraph, non gli agenti, sono l’anello debole