PT-2025-45384 · Langgraph · Langgraph

Published

2025-11-05

·

Updated

2025-12-15

·

CVE-2025-64439

CVSS v4.0

7.4

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions LangGraph versions 2.1.2 and below
Description LangGraph’s SQLite Checkpoint, which utilizes SQLite databases for checkpoint saving, contains a Remote Code Execution (RCE) issue in the JsonPlusSerializer when deserializing payloads saved in "json" serialization mode. The serializer defaults to "msgpack" but falls back to "json" if Unicode surrogate values cause serialization to fail. This issue allows for arbitrary code execution. The issue is addressed in version 3.0.0.
Recommendations Update to version 3.0.0 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-64439
GHSA-WWQV-P2PP-99H5

Affected Products

Langgraph