LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers to inject arbitrary SQL and bypass access controls. This vulnerability is fixed in 2.0.11.
History

Thu, 30 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Langchain
Langchain langchain
Langchain-ai
Langchain-ai langchain
Vendors & Products Langchain
Langchain langchain
Langchain-ai
Langchain-ai langchain

Wed, 29 Oct 2025 19:00:00 +0000

Type Values Removed Values Added
Description LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers to inject arbitrary SQL and bypass access controls. This vulnerability is fixed in 2.0.11.
Title LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-29T18:55:06.129Z

Updated: 2025-10-30T15:33:07.541Z

Reserved: 2025-10-27T15:26:14.127Z

Link: CVE-2025-64104

cve-icon Vulnrichment

Updated: 2025-10-30T15:32:56.347Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-29T19:15:39.220

Modified: 2025-10-30T16:15:36.777

Link: CVE-2025-64104

cve-icon Redhat

No data.