CVE-2026-28277 affects LangGraph SQLite Checkpoint versions 1.0.9 and prior, allowing for unsafe Python object reconstruction during deserialization of msgpack-encoded checkpoints. This vulnerability carries a CVSS score of 6.8 (Medium), indicating high impact on confidentiality, integrity, and availability, and requires high privileges and network access for exploitation. There is currently no public patch, active exploitation, or publicly available exploit code, and it has received no community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.9CPE matchmatch criteria | cpe:2.3:a:langchain:langgraph:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.