Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3859
  • PyPI/langgraph-checkpoint-mongodb
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure 10 Sep
  • Fix available
  • Severity - 7.7 (High)
GHSA-533j-2v4q-mw5h
  • PyPI/langgraph-checkpoint-mongodb
  • PyPI/langgraph-store-mongodb
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure 20 Aug
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-3636
  • PyPI/langgraph-checkpoint-sqlite
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores 10 Aug
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-3635
  • PyPI/langgraph-checkpoint-postgres
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores 10 Aug
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-47pj-3jcm-6whg
  • PyPI/langgraph-checkpoint-postgres
  • PyPI/langgraph-checkpoint-sqlite
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores 06 Aug
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2573
  • PyPI/langgraph-checkpoint
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading 13 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-2574
  • PyPI/langgraph-checkpoint
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution 13 Jul
  • Fix available
  • Severity - 6.6 (Medium)
PYSEC-2026-1530
  • PyPI/langgraph-checkpoint-sqlite
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method 07 Jul
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-1527
  • PyPI/langgraph-checkpoint
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer 07 Jul
  • Fix available
  • Severity - 7.4 (High)
PYSEC-2026-1529
  • PyPI/langgraph-checkpoint-sqlite
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore 07 Jul
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-1528
  • PyPI/langgraph-checkpoint-sqlite
LangGraph's SQLite store implementation has a SQL Injection Vulnerability 07 Jul
  • Fix available
  • Severity - 7.3 (High)
GHSA-fjqc-hq36-qh5p
  • PyPI/langgraph-checkpoint
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading 25 Jun
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-mhr3-j7m5-c7c9
  • PyPI/langgraph-checkpoint
LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution 25 Feb
  • Fix available
  • Severity - 6.6 (Medium)
GHSA-9rwj-6rc7-p77c
  • PyPI/langgraph-checkpoint-sqlite
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method 10 Dec 2025
  • Fix available
  • Severity - 7.3 (High)
GHSA-wwqv-p2pp-99h5
  • PyPI/langgraph-checkpoint
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer 05 Nov 2025
  • Fix available
  • Severity - 7.4 (High)
GHSA-7p73-8jqx-23r8
  • PyPI/langgraph-checkpoint-sqlite
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore 29 Oct 2025
  • Fix available
  • Severity - 7.3 (High)