Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
LangGraph Vulnerability Exposes Servers to Remote Attacks

LangGraph Vulnerability Exposes Servers to Remote Attacks

Posted on June 13, 2026 By CWS

A significant security flaw has been identified in LangGraph, a widely-used open-source framework for AI agents, which could potentially allow attackers to execute remote code and gain complete control over targeted servers. This vulnerability was discovered by Check Point Research, highlighting the increased risk posed by traditional vulnerabilities when integrated into AI systems managing sensitive operations.

The Extent of LangGraph’s Usage

LangGraph is favored for creating AI agents capable of handling complex processes using large language models. Its popularity is evident, with approximately 46.5 million downloads each month, and it is implemented across a variety of production settings. These include enterprise automation tools, customer support platforms, and internal business applications.

The widespread use of LangGraph amplifies the consequences of any security weaknesses within it. The identified vulnerability chain specifically targets the framework’s checkpointing mechanism, responsible for storing and retrieving AI agent states.

Details of the Vulnerability Chain

Check Point researchers found that the get_state_history() function within LangGraph’s SQLite checkpointer is vulnerable to SQL injection attacks due to a flaw in its filter parameter. This issue alone poses a significant threat but becomes critical when paired with another vulnerability involving unsafe msgpack deserialization.

Exploiting these vulnerabilities in tandem allows an attacker to inject harmful data, which can then be executed upon deserialization. This chain of vulnerabilities results in full remote code execution, illustrating how seemingly moderate issues can combine to create severe security breaches within core AI framework components.

Three CVEs have been assigned to document these vulnerabilities: CVE-2025-67644, CVE-2026-28277, and CVE-2026-27022, addressing issues from SQL injection to remote code execution.

Impact and Mitigation

The vulnerabilities primarily affect self-hosted setups using SQLite or Redis checkpointers with user input. It is important to note that LangSmith, the managed platform by LangChain, remains unaffected. If exploited, these vulnerabilities can expose sensitive information managed by AI agents, such as API keys, customer data, and internal system credentials.

Moreover, compromised servers can become launch pads for further attacks within internal networks, significantly escalating the potential threat.

All identified vulnerabilities have been addressed in updated versions of the software. Users are urged to update to secure versions, including langgraph-checkpoint-sqlite 3.0.1 or later, langgraph 1.0.10 or later, and langgraph-checkpoint-redis 1.0.2 or later, to mitigate these risks immediately.

This incident underscores the critical need for robust security measures in AI frameworks, as traditional vulnerabilities can lead to severe consequences in systems with elevated access and functionality.

Cyber Security News Tags:AI framework, AI security, Check Point, CVE, Cybersecurity, LangGraph, Open Source, RCE, SQL injection, Vulnerability

Post navigation

Previous Post: Alert Fatigue: A Growing Security Challenge
Next Post: Security Flaws in OpenClaw AI: New Research Reveals Risks

Related Posts

Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack Fake Fortinet Sites Steal VPN Credentials in Sophisticated Phishing Attack Cyber Security News
HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface HydraPWK Penetration Testing OS With Necessary Hacking Tools and Simplified Interface Cyber Security News
AI App Data Breach Exposes Millions of User Messages AI App Data Breach Exposes Millions of User Messages Cyber Security News
GitHub Strengthens Actions Security with New Checkout Update GitHub Strengthens Actions Security with New Checkout Update Cyber Security News
Patchwork APT Using PowerShell Commands to Create Scheduled Task and Downloads Final Payload Patchwork APT Using PowerShell Commands to Create Scheduled Task and Downloads Final Payload Cyber Security News
Hacker Pleads Guilty For Stealing Supreme Court Documents and Leaking via Instagram Hacker Pleads Guilty For Stealing Supreme Court Documents and Leaking via Instagram Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Global Outage Affects Claude AI Users with Overload Errors
  • DataBahn Secures $40M to Enhance Data Management Solutions
  • AI Network Firewalls: Revolutionizing Cybersecurity
  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Global Outage Affects Claude AI Users with Overload Errors
  • DataBahn Secures $40M to Enhance Data Management Solutions
  • AI Network Firewalls: Revolutionizing Cybersecurity
  • Ransomware Threat via Microsoft Teams Grows
  • Cantina Secures $8M for Autonomous Security Innovation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark