Skip to content
HighVulnerability

GHSA-wwqv-p2pp-99h5: LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer

Published
Record updated
View JSON
Affected
  • langgraph-checkpoint < 3.0.0
Fixed in
3.0.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.9%

Summary

Prior to langgraph-checkpoint version 3.0, the JsonPlusSerializer used as the default checkpoint serializer contains a remote code execution flaw when deserializing payloads saved in the "json" mode. An attacker who can get the application to persist a crafted payload in that mode can run arbitrary Python code on load, and the fallback to "json" can be triggered when surrogate values make msgpack serialization fail.

Mitigation

Fixed in langgraph-checkpoint==3.0.0. Upgrade immediately to langgraph-checkpoint==3.0.0. For langgraph-api deployments, any version 0.5 or later is also free of this vulnerability.