Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2750▲ 27 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.6) | — | — | Langchain Langgraph SDKAI | 2/10/2026 | 2/10/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and… | |
| Pendiente de análisis | Alta (7.7) | 0.53% | — | Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI | 14/9/2026 | 30/9/2026 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively… | |
| Aplazada | Media (5.9) | 0.26% | — | Langchain Langgraph-apiAI | 14/9/2026 | 30/9/2026 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dispatching assistants.search with an incomplete value instead of the assistants.read event used by direct reads and cron creation. In… | |
| Aplazada | Media (5.9) | 0.36% | — | Langchain Langgraph-apiAI | 14/9/2026 | 30/9/2026 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the authentication middleware treats that transport as internal without applying the… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langchain Langgraph Checkpoint PostgresAILangchain Langgraph Checkpoint SqliteAI | 6/8/2026 | 10/9/2026 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string… | |
| Pendiente de análisis | Media (6.7) | 0.36% | — | Langchain Langgraph-checkpoint-mongodbAI | 4/8/2026 | 9/9/2026 | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, checkpoint_id) from config.configurable are passed into MongoDB find() queries in… | |
| Aplazada | Baja (1.3) | 0.23% | — | Langchain LanggraphAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak hash. The attack is possible to be… | |
| Analizada | Crítica (9.1) | 0.29% | — | Langchain Langgraph-sdk | 17/6/2026 | 26/6/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource operations. Without… | |
| Analizada | Media (6.8) | 0.69% | — | Langchain Langgraph-checkpoint | 16/6/2026 | 24/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSerializer can reconstruct Python objects from JSON checkpoint payloads. Under conditions where someone could modify checkpoint bytes at rest… | |
| Analizada | Alta (7.2) | 0.70% | — | Langchain Langgraph | 5/3/2026 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint… | |
| Aplazada | Media (6.6) | 0.96% | — | Langchain Langgraph CheckpointAI | 25/2/2026 | 17/6/2026 | LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseCache` and opt nodes into caching via `CachePolicy`. Prior to… | |
| Aplazada | Media (6.5) | 0.49% | — | Langchain Langgraph-checkpoint-redisAI | 20/2/2026 | 17/6/2026 | @langchain/langgraph-checkpoint-redis is the Redis checkpoint and store implementation for LangGraph. A query injection vulnerability exists in the @langchain/langgraph-checkpoint-redis package's filter handling. The RedisSaver and ShallowRedisSaver classes construct RediSearch queries by directly interpolating… | |
| Analizada | Alta (7.8) | 2.3% | — | Langchain Langgraph-checkpoint-sqlite | 11/12/2025 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metadata filter keys,… | |
| Aplazada | Alta (7.4) | 0.88% | — | Langchain LanggraphAI | 7/11/2025 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2.1.2 and below, the JsonPlusSerializer (used as the default serialization protocol for all checkpointing) contains a Remote Code Execution (RCE) vulnerability when… | |
| Aplazada | Alta (7.3) | 0.19% | — | Langchain LanggraphAI | 29/10/2025 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers… | |
| Aplazada | Alta (7.3) | 0.18% | — | Langchain Langgraph-checkpoint-sqliteAILangchainAI | 26/10/2025 | 17/6/2026 | A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct… |