Critical Vulnerabilities in LangGraph AI Framework Enable Full Server Control

Critical Vulnerabilities in LangGraph AI Framework Enable Full Server Control

4h ago Blog.CheckpointCybersecuritynewsEscudodigital 72% similarity 72.6
Share:

Article Content

Browse articles
ThreatCluster

Check Point Research identified critical vulnerabilities in LangGraph, an AI framework with 46.5 million downloads last month. The flaws allow attackers to execute remote code and gain control over affected servers. The vulnerabilities stem from an SQL injection in the get_state_history() function combined with a deserialization issue. These issues can lead to unauthorized access to sensitive data, including API keys and conversation histories. LangGraph is widely used for automating tasks in corporate environments, making the impact potentially severe. The vulnerabilities have been assigned three CVEs, and the LangChain team is working on fixes. Organizations using LangGraph are advised to monitor their systems closely and apply patches once available.

Key Points: • LangGraph has 46.5 million downloads, making its vulnerabilities highly impactful. • An SQL injection combined with a deserialization flaw enables remote code execution. • Three CVEs have been assigned, and organizations should prepare for imminent patches.

ThreatCluster AI

Timeline

2025-12-10
CVE-2025-67644 published
A vulnerability affecting LangGraph was published, contributing to security risks.
Date unknown
2026-02-20
CVE-2026-27022 published
Another critical vulnerability in LangGraph was disclosed, increasing the risk profile.
Date unknown
2026-03-05
CVE-2026-28277 published
A critical vulnerability in LangGraph was disclosed, allowing remote code execution.
Escudodigital
2026-06-12
Vulnerability chain discovered
Check Point Research revealed a critical vulnerability chain in LangGraph, enabling full server control.
Blog.Checkpoint
2026-06-12
LangGraph vulnerability impact highlighted
The vulnerabilities were reported to affect numerous corporate environments using LangGraph.
Cybersecuritynews

Community

Browse all →