Vulnerabilities & PatchesEmerging1 src
From SQLi to RCE – Exploiting LangGraph’s Checkpointer
By Yarden Porat
AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state. But what happens when that persistence layer isn’t locked down?
Key Points
• Check Point Research analyzed LangGraph , an open-source framework for stateful AI agents with over 50 million monthly downloads, and uncovered three vulnerabilities in its persistence layer.
• Two of them chain into remote code execution : a SQL injection in the SQLite checkpointer ( CVE-2025-67644 ) and an unsafe msgpack deserialization ( CVE-2026-28277 ).
• A third, parallel issue ( CVE-2026-27022 ) introduces the same injection class into the Redis checkpointer.
• Who’s at risk: teams self-hosting LangGraph with the SQLite or Redis checkpointer, where the application exposes get_state_history() with a user-controlled filter .
CVE-2025-67644CVE-2026-28277CVE-2026-27022