CVE-2026-48121
- EPSS 0.23%
- Veröffentlicht 04.08.2026 16:49:57
- Zuletzt bearbeitet 04.08.2026 20:16:51
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id)...
CVE-2026-14742
- EPSS 0.16%
- Veröffentlicht 05.07.2026 10:45:09
- Zuletzt bearbeitet 06.07.2026 19:16:58
A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_...
CVE-2026-28277
- EPSS 4.93%
- Veröffentlicht 05.03.2026 19:10:36
- Zuletzt bearbeitet 21.04.2026 15:14:55
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python o...