<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:06:54 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-48775 — LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-48775</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langchain-ai langgraph, langchain-ai langraph-checkpoint&lt;/p&gt;
&lt;p&gt;LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning &amp;#34;checkpoint-store write access&amp;#34; into code execution in the application runtime. This issue has been fixed in version 4.1.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langchain-ai langgraph, langchain-ai langraph-checkpoint&lt;/p&gt;
&lt;p&gt;LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time. This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning &amp;#34;checkpoint-store write access&amp;#34; into code execution in the application runtime. This issue has been fixed in version 4.1.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-48775</guid>
    </item>
    <item>
      <title>GHSA-fjqc-hq36-qh5p — LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fjqc-hq36-qh5p</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langgraph-checkpoint&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;LangGraph&amp;#39;s `JsonPlusSerializer` can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time.&lt;/p&gt;
&lt;p&gt;This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning &amp;#34;checkpoint-store write access&amp;#34; into code execution in the application runtime.&lt;/p&gt;
&lt;p&gt;There is no evidence of this behavior being triggered in the wild, and the team is not aware of a practical path to it in existing deployments today. This change is intended to reduce the surface available after a checkpoint-store incident.&lt;/p&gt;
&lt;p&gt;## Affected users / systems&lt;/p&gt;
&lt;p&gt;Users may be affected if they:&lt;/p&gt;
&lt;p&gt;- use a persistent checkpointer (database, remote store, shared filesystem, etc.) with the default `JsonPlusSerializer`,
- load/resume from checkpoints, and
- operate in an environment where write access to the checkpoint store could be obtained by an unauthorized party.&lt;/p&gt;
&lt;p&gt;The default checkpoint serializer in all shipped checkpointer backends (`PostgresSaver`, `SqliteSaver`, and their async counterparts) is `JsonPlusSerializer`, so applications generally do not need to opt in to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langgraph-checkpoint&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;LangGraph&amp;#39;s `JsonPlusSerializer` can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest in the backing store, the deserialization path could reconstruct objects beyond what the application expects, which could in turn result in code execution at checkpoint load time.&lt;/p&gt;
&lt;p&gt;This is a defense-in-depth issue. The affected behavior is reachable only when checkpoint bytes at rest in the backing store can be modified by an unauthorized party. In most deployments that prerequisite already implies a serious incident; the additional concern is turning &amp;#34;checkpoint-store write access&amp;#34; into code execution in the application runtime.&lt;/p&gt;
&lt;p&gt;There is no evidence of this behavior being triggered in the wild, and the team is not aware of a practical path to it in existing deployments today. This change is intended to reduce the surface available after a checkpoint-store incident.&lt;/p&gt;
&lt;p&gt;## Affected users / systems&lt;/p&gt;
&lt;p&gt;Users may be affected if they:&lt;/p&gt;
&lt;p&gt;- use a persistent checkpointer (database, remote store, shared filesystem, etc.) with the default `JsonPlusSerializer`,
- load/resume from checkpoints, and
- operate in an environment where write access to the checkpoint store could be obtained by an unauthorized party.&lt;/p&gt;
&lt;p&gt;The default checkpoint serializer in all shipped checkpointer backends (`PostgresSaver`, `SqliteSaver`, and their async counterparts) is `JsonPlusSerializer`, so applications generally do not need to opt in to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fjqc-hq36-qh5p</guid>
    </item>
  </channel>
</rss>
