CVE-2026-104873
- EPSS 0.25%
- Veröffentlicht 02.10.2026 20:17:01
- Zuletzt bearbeitet 06.10.2026 15:08:38
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth...
CVE-2026-48121
- EPSS 0.23%
- Veröffentlicht 04.08.2026 16:49:57
- Zuletzt bearbeitet 09.09.2026 20:50:00
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id)...
CVE-2026-14742
- EPSS 0.16%
- Veröffentlicht 05.07.2026 10:45:09
- Zuletzt bearbeitet 06.07.2026 19:16:58
A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_...
CVE-2026-28277
- EPSS 4.93%
- Veröffentlicht 05.03.2026 19:10:36
- Zuletzt bearbeitet 21.04.2026 15:14:55
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python o...