logo

LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks

ID: adeb7a86-410c-5dff-b16a-36fef9e27ac9

STIX ID: report--adeb7a86-410c-5dff-b16a-36fef9e27ac9

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-27

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Cybersecurity researchers disclosed three serious vulnerabilities in LangChain and LangGraph — a path traversal (CVE-2026-34070), unsafe deserialization leaking API keys and secrets (CVE-2025-68664), and an SQL injection in LangGraph's SQLite checkpoint (CVE-2025-67644) — that could allow attackers to read files, siphon secrets, and access conversation history; patches for the affected versions have been released and users are urged to update promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.