Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LangGraph Vulnerabilities Risk Remote Code Execution

LangGraph Vulnerabilities Risk Remote Code Execution

Posted on June 13, 2026 By CWS

Recent revelations from cybersecurity experts have shed light on three critical security vulnerabilities within LangGraph, an open-source AI framework by LangChain, which have since been patched. Notably, these flaws include a vulnerability chain that could lead to remote code execution, posing a significant threat to the system’s integrity.

Understanding LangGraph and Its Vulnerabilities

LangGraph, designed to facilitate the development of complex AI applications, was found to harbor several security weaknesses. Among them, a crucial SQL injection vulnerability was identified, potentially allowing attackers to gain control of the server by manipulating data processing mechanisms.

The specific vulnerabilities, identified as CVE-2025-67644, CVE-2026-28277, and CVE-2026-27022, were found within various components of LangGraph’s infrastructure, such as SQLite and Redis implementations. These security flaws allowed for SQL query manipulation and unsafe deserialization, thereby compromising system security.

Details of the Security Flaws

The SQL injection vulnerability, tagged CVE-2025-67644, affects versions of langgraph-checkpoint-sqlite before 3.0.1 and allows attackers to alter SQL queries via metadata filters. The unsafe msgpack deserialization, CVE-2026-28277, affects versions before 1.0.10, facilitating object reconstruction by attackers who can modify checkpoint data. Lastly, CVE-2026-27022 involves a RediSearch Query Injection, enabling access bypass in versions of @langchain/langgraph-checkpoint-redis prior to 1.0.1.

Exploiting these vulnerabilities requires specific conditions, as detailed by Check Point. The attack chain utilizes the get_state_history() endpoint, enabling attackers to retrieve and manipulate historical checkpoints through a series of steps involving malicious payloads and filter parameters.

Security Implications and Recommendations

These vulnerabilities highlight how traditional security issues, such as SQL injection, can become more dangerous within AI frameworks due to their elevated access and trust levels. Check Point emphasizes the potential for sensitive data exposure, stressing the importance of addressing these vulnerabilities promptly.

To safeguard against such threats, users are advised to update their systems with the latest patches, implement robust authentication measures for self-hosted LangGraph servers, and adhere to security best practices, such as network segmentation and the principle of least privilege.

The discovery of these vulnerabilities underscores the critical need for ongoing vigilance and proactive measures to secure AI frameworks and the sensitive data they manage.

The Hacker News Tags:AI framework, AI security, Check Point, CVE, Cybersecurity, Langchain, LangGraph, msgpack deserialization, RediSearch injection, remote code execution, security flaws, self-hosted security, SQL injection, Vulnerability

Post navigation

Previous Post: Google Sues Chinese Group Over AI-Driven Cyberattacks
Next Post: Oracle PeopleSoft Vulnerability Exploited by ShinyHunters

Related Posts

Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature The Hacker News
From MCPs and Tool Access to Shadow API Key Sprawl From MCPs and Tool Access to Shadow API Key Sprawl The Hacker News
Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms Critical Lanscope Endpoint Manager Bug Exploited in Ongoing Cyberattacks, CISA Confirms The Hacker News
Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows The Hacker News
 Google Sues China-Based Hackers Behind  Billion Lighthouse Phishing Platform  Google Sues China-Based Hackers Behind $1 Billion Lighthouse Phishing Platform The Hacker News
GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops
  • CISA Urges Agencies to Address High-Risk Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GreatXML Exploit Circumvents Windows BitLocker Security
  • Anthropic Pauses AI Models Amid U.S. Export Controls
  • U.S. Halts Foreign Access to Anthropic’s AI Models
  • SHEETCREEP RAT Exploits Google Sheets for Covert Ops
  • CISA Urges Agencies to Address High-Risk Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark