Please use LangChain VDP and LangChain Open Source VDP to report security vulnerabilities.
Security: langchain-ai/langgraph
Security
SECURITY.md
-
Namespace prefix matching crosses segment boundaries in Postgres and SQLite storesGHSA-47pj-3jcm-6whg published
Jul 30, 2026 by nick-hollon-lcModerate -
Unsafe URL path construction in LangGraph SDKGHSA-w39p-vh2g-g8g5 published
May 22, 2026 by nick-hollon-lcModerate -
Unsafe JSON deserialization in LangGraph checkpoint loadingGHSA-fjqc-hq36-qh5p published
May 22, 2026 by nick-hollon-lcModerate -
Unsafe msgpack deserialization in LangGraph checkpoint loadingGHSA-g48c-2wqr-h844 published
Mar 5, 2026 by jkennedyvzModerate -
ZDI-CAN-28385: LangChain LangGraph BaseCache Deserialization of Untrusted Data Remote Code Execution VulnerabilityGHSA-mhr3-j7m5-c7c9 published
Feb 23, 2026 by eyurtsevModerate -
SQL injection via metadata filter key in SQLite checkpointer list methodGHSA-9rwj-6rc7-p77c published
Dec 9, 2025 by eyurtsevHigh -
RCE in "json" mode of JsonPlusSerializerGHSA-wwqv-p2pp-99h5 published
Nov 5, 2025 by eyurtsevHigh -
SQLite Filter Key SQL Injection POC for SqliteStoreGHSA-7p73-8jqx-23r8 published
Oct 29, 2025 by eyurtsevHigh
Learn more about advisories related to langchain-ai/langgraph in the GitHub Advisory Database