Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48775

Опубликовано: 16 июн. 2026
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning "checkpoint-store write access" into code execution in the application runtime. This issue has been fixed in version 4.1.1.

A flaw was found in LangGraph. This vulnerability allows an attacker with high privileges and adjacent network access to modify checkpoint data. By manipulating these stored checkpoint bytes, an attacker can trigger insecure deserialization, leading to arbitrary code execution when the checkpoint is loaded. This issue is considered a defense-in-depth concern, as it requires prior unauthorized access to the checkpoint's backing store.

Отчет

A flaw was found in LangGraph's SQLite checkpoint implementation. The JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. If an attacker gains write access to the checkpoint backing store, they can modify checkpoint bytes to achieve code execution at checkpoint load time. This is a defense-in-depth issue — the prerequisite of checkpoint-store write access already implies a serious incident in most deployments.

Меры по смягчению последствий

Upgrade to LangGraph checkpoint version 4.1.1 or later. As a defense-in-depth measure, restrict write access to the checkpoint backing store to only trusted application components.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-autorag-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-nemo-guardrails-server-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2489358langgraph: langgraph-checkpoint: LangGraph: Arbitrary code execution via insecure deserialization of modified checkpoint bytes

EPSS

Процентиль: 14%
0.00232
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
около 2 месяцев назад

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning "checkpoint-store write access" into code execution in the application runtime. This issue has been fixed in version 4.1.1.

CVSS3: 6.8
github
около 1 месяца назад

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

EPSS

Процентиль: 14%
0.00232
Низкий

6.4 Medium

CVSS3