CVE 7.3 HIGH

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore_CVE-2025-64104

7.3 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Description

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers to inject arbitrary SQL and bypass access controls. This vulnerability is fixed in 2.0.11.

Basic Information

ID CVE-2025-64104
Source GitHub_M
Published Oct 29, 2025 at 18:55

Affected Product

Vendor langchain-ai
Product langgraph
Version < 2.0.11
Affected Versions langchain-ai langgraph < 2.0.11

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.