HighVulnerability
GHSA-wwqv-p2pp-99h5: LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
- Identifiers
- CVE-2025-64439GHSA-wwqv-p2pp-99h5
- Published
- Record updated
- Affected
- langgraph-checkpoint < 3.0.0
- Fixed in
- 3.0.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.9%
Summary
Prior to langgraph-checkpoint version 3.0, the JsonPlusSerializer used as the default checkpoint serializer contains a remote code execution flaw when deserializing payloads saved in the "json" mode. An attacker who can get the application to persist a crafted payload in that mode can run arbitrary Python code on load, and the fallback to "json" can be triggered when surrogate values make msgpack serialization fail.
Mitigation
Fixed in langgraph-checkpoint==3.0.0. Upgrade immediately to langgraph-checkpoint==3.0.0. For langgraph-api deployments, any version 0.5 or later is also free of this vulnerability.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- langgraph-checkpointPyPILLM dependency since 2024-08-02 · 7 tracked dependents
Related items
- HighCVE-2026-106119: LangChain MongoDBChatMessageHistory query injection via session identifierSame vendor · NVD/CVE Database
- LowGHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text ValuesSame vendor · GitHub Advisory Database
- HighGHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decoratorsSame vendor · GitHub Advisory Database
- HighCVE-2026-72848: SitemapLoader nested sitemap entries bypass restrict_to_same_domainSame vendor · NVD/CVE Database
- HighGHSA-533j-2v4q-mw5h: LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposureSame vendor · GitHub Advisory Database