Логотип exploitDog
bind:CVE-2025-8709
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-8709

Количество 2

Количество 2

nvd логотип

CVE-2025-8709

4 месяца назад

A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers to inject arbitrary SQL, leading to unauthorized access to all documents, data exfiltration of sensitive fields such as passwords and API keys, and a complete bypass of application-level security filters.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-4h97-wpxp-3757

4 месяца назад

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-8709

A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers to inject arbitrary SQL, leading to unauthorized access to all documents, data exfiltration of sensitive fields such as passwords and API keys, and a complete bypass of application-level security filters.

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-4h97-wpxp-3757

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

CVSS3: 7.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу