Close Menu
    What's Hot

    AIPAC Wants Democrats to Back Israel. Instead, They’re Turning on AIPAC.

    Iran War Live Updates: Tense Calm Grips Mideast as Trump Again Claims Deal Is Close

    Why AI that works in the lab often fails in production — and what actually fixes it

    Facebook X (Twitter) Instagram
    Trending
    • AIPAC Wants Democrats to Back Israel. Instead, They’re Turning on AIPAC.
    • Iran War Live Updates: Tense Calm Grips Mideast as Trump Again Claims Deal Is Close
    • Why AI that works in the lab often fails in production — and what actually fixes it
    • Amazon claims data centers 7x more water-efficient than rivals
    • Pedal Electric H/T Review: A Fast, Powerful, Stylish Ebike
    • Wall Street Breakfast Podcast: SpaceX Enters Public Orbit
    • Jude Bellingham: England got things wrong off the pitch at Euro 2024 | Football News
    • Japan captain Wataru Endo out of World Cup with injury, announces international retirement
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

    adminBy adminJune 12, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 12, 2026Vulnerability / AI Security

    LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

    Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution.

    LangGraph is an open-source framework created by LangChain to build complex, stateful, and multi-agent artificial intelligence (AI) agentic applications.

    “An SQL injection in LangGraph’s function could allow attackers to gain full control via remote code execution of a server by exploiting weaknesses in how the system processes and handles data,” Check Point said.

    The list of identified vulnerabilities is as follows –

    • CVE-2025-67644 (CVSS score: 7.3) – A SQL injection vulnerability exists in LangGraph’s SQLite checkpoint implementation that allows attackers to manipulate SQL queries through metadata filter keys. (Affects langgraph-checkpoint-sqlite versions before 3.0.1)
    • CVE-2026-28277 (CVSS score: 6.8) – An unsafe msgpack deserialization vulnerability in LangGraph that could be used to trigger object reconstruction when a checkpoint is loaded by an attacker who can modify checkpoint data. (Affects langgraph versions before 1.0.10)
    • CVE-2026-27022 (CVSS score: 6.5) – A RediSearch Query Injection in @langchain/langgraph-checkpoint-redis that can be used to bypass access controls. (Affects @langchain/langgraph-checkpoint-redis versions before 1.0.1)

    “The vulnerability chain is exploitable in self-hosted deployments using the SQLite or Redis checkpointer with user-controlled filter input,” Check Point said. “LangChain’s managed platform (LangSmith Deployment), is not affected.”

    Cybersecurity

    Security researcher Yarden Porat, who is credited with discovering and reporting all three flaws, said CVE-2025-67644 and CVE-2026-28277 could be chained to achieve remote code execution.

    Specifically, the attack chain hinges on the application exposing the get_state_history() endpoint, which then allows an attacker to retrieve historical checkpoints based on their metadata. It requires the following steps –

    • The attacker prepares a msgpack payload containing instructions to execute arbitrary code.
    • The attacker sends a malicious filter parameter that exploits the SQL injection vulnerability to return a fake checkpoint row to the database query results, where the checkpoint column contains attacker-controlled serialized data.
    • When the application processes the query results, it deserializes the malicious checkpoint’s BLOB.
    • The attacker exploits the unsafe deserialization vulnerability to execute the attacker’s payload, giving them remote code execution on the server.

    LangGraph has described CVE-2026-28277 as a post-exploitation issue, where successful exploitation requires the ability to write attacker-controlled checkpoint data and turn that into code execution in the application runtime, and it does not pose any risks to existing LangSmith-hosted deployments.

    In such a scenario, this escalation from write access to checkpoint store” to code execution may “expose runtime secrets or provide access to other systems the runtime can reach,” LangGraph maintainers said. “The described threat model requires an attacker to tamper with the checkpoint persistence layer used by the deployment; typical hosted configurations are designed to prevent such access.”

    Check Point said the findings illustrate how classic vulnerability classes like SQL injection can become more potent when they manifest inside AI agent frameworks that carry elevated access and trust, thereby opening the door to sensitive data exposure.

    Users are advised to apply the latest fixes, implement authentication for self-hosted LangGraph servers, avoid long-lived static secrets, enforce network segmentation, treat AI agents as privileged identities, and apply the principle of least privilege (PoLP) to limit the agent’s access footprint.

    agents Chain Code Execution Exposes flaw LangGraph remote selfhosted
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleThe battery startup powering the laser-weapons race
    Next Article You Probably Won’t Get Rich Off the SpaceX IPO
    admin
    • Website

    Related Posts

    Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs

    June 12, 2026

    Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories

    June 12, 2026

    Coinbase’s new tool can help agents trade and pay for premium research

    June 12, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    AIPAC Wants Democrats to Back Israel. Instead, They’re Turning on AIPAC.

    Iran War Live Updates: Tense Calm Grips Mideast as Trump Again Claims Deal Is Close

    Why AI that works in the lab often fails in production — and what actually fixes it

    Amazon claims data centers 7x more water-efficient than rivals

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by