logo

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

ID: 553b8027-5892-521a-9872-9cb742508dee

STIX ID: report--553b8027-5892-521a-9872-9cb742508dee

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: [email protected] (The Hacker News)

...
...

**Researchers disclosed three patched vulnerabilities in LangGraph that affect self-hosted deployments: an SQL injection in the SQLite checkpoint implementation (CVE-2025-67644), unsafe msgpack deserialization (CVE-2026-28277), and a RediSearch query injection (CVE-2026-27022). Check Point and the researcher show the SQLi and unsafe deserialization can be chained—via the get_state_history endpoint—to deserialize attacker-controlled checkpoints and achieve remote code execution; LangChain's managed LangSmith service is not impacted. Users are advised to apply patches, enforce authentication and network segmentation, and follow least-privilege practices.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.