Security Digest: October 29, 2025 - 1 Critical Vulnerability
A critical SQL injection vulnerability, CVE-2025-64104, has been discovered in LangGraph’s SQLite store implementation. This flaw could allow attackers to inject arbitrary SQL and bypass access controls.
· 2 min read
Critical SQL Injection Threat in LangGraph's SQLite Store
Executive Summary
A critical SQL injection vulnerability, CVE-2025-64104, has been discovered in LangGraph’s SQLite store implementation. This flaw could allow attackers to inject arbitrary SQL and bypass access controls. Immediate action is required to prevent potential data breaches.
Critical Vulnerabilities
CVE-2025-64104: SQL Injection in LangGraph SQLite Store
- Impact: Attackers can inject arbitrary SQL, potentially accessing or manipulating sensitive data.
- Affected Systems: Projects using the
checkpoint-sqlitestore from LangGraph, especially if they use untrusted input for filter keys. - Immediate Action: Audit code for direct concatenation of untrusted input into SQL queries. Implement proper parameterization immediately.
- Mitigation: Use allowlisting for filter keys or switch to parameterized queries to prevent injection.
Previously Alerted
What to Do Now
- Review all usages of
SqliteStorein your projects for potential injection points. - Implement input validation and parameterized queries to sanitize inputs.
- Deploy patches or workarounds as recommended in vendor advisories.
- Verify your fixes by testing applications with known injection payloads.
- Continuously monitor your systems for unusual access patterns or data anomalies.
Related Resources
- Check internal blog posts for detailed mitigation strategies.
- Refer to official LangGraph advisories for patches and updates.