GHSA-wwqv-p2pp-99h5
HIGHCVE-2025-64439Prior to langgraph-checkpoint version 3.0 , LangGraph’s JsonPlusSerializer (used as the default serialization protocol for all checkpointing) contains a remote code execution (RCE) vulnerability when deserializing payloads saved in the "json" serialization mode.
- Affected
- < 3.0.0
- Fixed in
- 3.0.0
- Weakness
- CWE-502
- Published
- 2025-11-05
- Source
- github