SQL Injection Vulnerability in LangGraph SQLite Checkpoint Implementation
CVE-2025-64104
7.3HIGH
What is CVE-2025-64104?
LangGraph SQLite Checkpoint contains vulnerabilities due to its use of direct string concatenation in SQL queries without proper parameterization. This oversight allows attackers to perform SQL injection attacks, potentially manipulating the database and bypassing access controls. Users are advised to upgrade to version 2.0.11 or later to mitigate these risks.
Affected Version(s)
langgraph < 2.0.11
