A newly disclosed critical vulnerability chain in LangGraph, an open-source AI agent framework from the creators of LangChain, warns that attackers can exploit the flaws to achieve full remote code execution (RCE) on self-hosted deployments.
According to Checkpoint, with approximately 46.5 million monthly downloads, LangGraph is among the world’s most widely adopted AI agent platforms, making the severity of this disclosure especially significant for enterprise environments.
The vulnerability chain originates in LangGraph’s get_state_history() function, which is responsible for retrieving historical agent checkpoints from a persistence layer.
The checkpointer saves an agent’s execution state at each step, essentially functioning as the AI agent’s memory and is deeply embedded in the framework’s core execution path.
Critical LangGraph Vulnerabilities
The first flaw, CVE-2025-67644 (CVSS 7.3), is an SQL injection vulnerability in the SQLite checkpointer’s _metadata_predicate() function.
The function directly interpolates user-controlled metadata filter keys into SQL query strings using unsafe f-string formatting, for example, json_extract(CAST(metadata AS TEXT), '$.{query_key}') without any validation or sanitization.
This allows an attacker to inject arbitrary SQL and manipulate which checkpoint data is returned from the database.
On its own, that would be serious. But the second vulnerability results in a full server compromise. CVE-2026-28277 is an unsafe msgpack deserialization flaw in LangGraph’s checkpoint loading mechanism.

Because LangGraph processes the checkpoint data it retrieves from the database, an attacker who manipulates that data via SQL injection can feed a crafted msgpack payload, one that reconstructs malicious Python objects during deserialization, and ultimately triggers os.system() execution on the underlying server.
A third flaw, CVE-2026-27022, covers a similar query injection issue in the Redis checkpointer backend.
The flow diagram above captures this chain precisely: from the exposed get_state_history() API, through the vulnerable sqliteSaver.list() call, into the UNION-injected SQL query, through loads_typed("msgpack", checkpoint), into _msgpack_ext_hook(code, bytes), and finally to os.system(command).
A successful exploit hands an attacker far more than a foothold. A compromised LangGraph server exposes LLM API keys, full conversation history, CRM credentials, customer PII, and a direct pivot point into internal networks, effectively everything the AI agent ever touched.
Checkpoint stated that this distinguishes the attack from a simple prompt injection, which affects only a single session. Full server compromise means persistent, retrospective access to all agent operations.
Affected and Patch Status
The vulnerability chain is exploitable only in self-hosted deployments that use either the SQLite or Redis checkpointer and allow user-controllable filter input. LangChain’s managed platform uses PostgreSQL and is not affected. All three CVEs have now been patched:
- CVE-2025-67644 → upgrade to
langgraph-checkpoint-sqlite≥ 3.0.1 - CVE-2026-28277 → upgrade to
langgraph≥ 1.0.10 - CVE-2026-27022 → upgrade to
langgraph-checkpoint-redis≥ 1.0.2
This research highlights a dangerous pattern emerging across the AI ecosystem: classic vulnerability classes like SQL injection become exponentially more dangerous inside AI agent frameworks that carry elevated access, long-lived secrets, and trusted identities.
Teams running LangGraph in production should patch immediately, place the server behind proper authentication, apply least-privilege access to all agent credentials, and treat a compromised agent runtime with the same urgency as a compromised privileged account.
As AI agents become deeper integrations within enterprise infrastructure, securing their persistence and deserialization layers is no longer optional.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.