Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-48775— LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

Quick assessment

Affected
langchain-ai langgraph
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LangChain langgraph是LangChain公司开源的一个大模型框架。 LangChain langgraph存在安全漏洞,该漏洞源于JsonPlusSerializer可以从JSON检查点有效载荷重构Python对象,导致反序列化路径重构超出应用程序预期的对象,从而在检查点加载时可能导致代码执行。

CVSS 6.8 · Medium EPSS 0.69% · P51

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 2

VendorProduct Version RangeStatus
langchain-ai langgraph < 1.2.2 affected
langchain-ai langraph-checkpoint < 4.1.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48775

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
Source: CVE Program / CVE List V5
Vulnerability Description
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning "checkpoint-store write access" into code execution in the application runtime. This issue has been fixed in version 4.1.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5
Vulnerability Title
LangChain langgraph 反序列化漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LangChain langgraph是LangChain公司开源的一个大模型框架。 LangChain langgraph存在安全漏洞,该漏洞源于JsonPlusSerializer可以从JSON检查点有效载荷重构Python对象,导致反序列化路径重构超出应用程序预期的对象,从而在检查点加载时可能导致代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
langchain-ai langgraph < 1.2.2 -
langchain-ai langraph-checkpoint < 4.1.1 -

II. Public POCs for CVE-2026-48775

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48775

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-48775 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-48775

No comments yet


Leave a comment