LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
ID: 553b8027-5892-521a-9872-9cb742508dee
STIX ID: report--553b8027-5892-521a-9872-9cb742508dee
Feed Name: The Hacker News
**Researchers disclosed three patched vulnerabilities in LangGraph that affect self-hosted deployments: an SQL injection in the SQLite checkpoint implementation (CVE-2025-67644), unsafe msgpack deserialization (CVE-2026-28277), and a RediSearch query injection (CVE-2026-27022). Check Point and the researcher show the SQLi and unsafe deserialization can be chained—via the get_state_history endpoint—to deserialize attacker-controlled checkpoints and achieve remote code execution; LangChain's managed LangSmith service is not impacted. Users are advised to apply patches, enforce authentication and network segmentation, and follow least-privilege practices.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
