Published Security Advisories

GHSA ID Severity Summary CWEs Relevance
GHSA-g48c-2wqr-h844 Medium Unsafe msgpack deserialization in LangGraph checkpoint loading Directly relates to T1 — patched in 1.0.10, confirms attack path via crafted msgpack payloads
GHSA-mhr3-j7m5-c7c9 Medium BaseCache Deserialization RCE CWE-502 Directly relates to T1 — msgpack deserialization in cache layer
GHSA-9rwj-6rc7-p77c High SQL injection via metadata filter key in SQLite checkpointer CWE-89 Fixed via _validate_filter_key() regex — see D2
GHSA-wwqv-p2pp-99h5 High RCE in JSON mode of JsonPlusSerializer CWE-502 Directly relates to T3 — lc:2 constructor import
GHSA-7p73-8jqx-23r8 High SQLite Filter Key SQL Injection in SqliteStore CWE-89 Fixed via _validate_filter_key() regex — see D2

Pattern: 3 of 5 published advisories involve CWE-502 (insecure deserialization) in the checkpoint serialization layer. This confirms the checkpoint storage boundary (TB2) as the highest-risk area. The extensive closed advisory history (~15 deserialization bypass attempts) further validates this assessment. No new published advisories since the prior assessment (2026-03-27).