CVE-2025-64104: high-severity vulnerability in langchain-ai langgraph
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers to inject arbitrary SQL and bypass access controls. This vulnerability is fixed in 2.0.11.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Affected products
langchain-ai · langgraphRelated CVEs — langchain-ai langgraph
In the same product, most dangerous first.
CVE-2025-67644HIGHLangGraph SQLite Checkpoint is vulnerable to SQL Injection via metadata filter key in checkpointer list methodEPSS 2.3%CVE-2025-64439HIGHLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializerEPSS 0.9%CVE-2026-28277MEDIUMLangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loadingEPSS 0.7%CVE-2026-48775MEDIUMLangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loadingEPSS 0.7%CVE-2026-71433MEDIUMLangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite storesEPSS 0.4%CVE-2026-104873HIGHLangGraph SDK custom auth silently ignores actions= on resource decoratorsEPSS 0.3%