
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27794 is a Remote Code Execution (RCE) vulnerability in LangGraph Checkpoint's caching layer, classified as "LangGraph BaseCache Deserialization of Untrusted Data." It affects langgraph-checkpoint versions prior to 4.0.0 and was disclosed on February 23–25, 2026. The vulnerability stems from unsafe pickle deserialization when cache backends inheriting from BaseCache are explicitly enabled and nodes opt into caching via CachePolicy. It carries a CVSS v3.1 base score of 6.6 (Medium), assigned by GitHub as the CNA (GitHub Advisory, Red Hat CVE).
The root cause (CWE-502: Deserialization of Untrusted Data) lies in BaseCache defaulting to JsonPlusSerializer(pickle_fallback=True) in libs/checkpoint/langgraph/cache/base/__init__.py. When msgpack serialization fails, the JsonPlusSerializer.loads_typed() method in libs/checkpoint/langgraph/checkpoint/serde/jsonplus.py falls back to pickle.loads(data_) for entries stored as a ("pickle", ...) tuple. An attacker who can write a crafted pickle payload to the cache backend (e.g., Redis, SQLite, or in-memory cache) will trigger arbitrary code execution when the LangGraph process reads and deserializes that entry. Exploitation requires three preconditions: (1) the application explicitly enables a cache backend, (2) at least one node opts into caching via CachePolicy, and (3) the attacker has write access to the cache storage layer — making this a post-compromise escalation vector (GitHub Advisory, Patch PR).
Successful exploitation results in arbitrary code execution with the privileges of the LangGraph process, yielding full confidentiality, integrity, and availability compromise of the affected host. Attack scenarios include injecting malicious payloads into a network-accessible Redis instance with weak or no authentication, exploiting shared multi-tenant cache infrastructure, or writing to a writable SQLite cache file. Beyond direct process compromise, attackers may exfiltrate sensitive data processed by the LangGraph application, tamper with cached inference results, disrupt service availability, and potentially pivot laterally within the infrastructure (GitHub Advisory, Feedly).
A proof-of-concept exploit was published by Trend Micro's Zero Day Initiative (ZDI-26-135) on March 3, 2026, referenced under ZDI-CAN-28385 (ZDI Advisory). The vulnerability was discovered and reported by Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk of Trend Micro ZDI (GitHub Advisory). There is no current evidence of in-the-wild exploitation, and the CVE is not listed in the CISA KEV catalog. The EPSS score is approximately 0.32%, reflecting low but non-negligible exploitation probability given the PoC availability (Feedly).
langgraph-checkpoint < 4.0.0, has explicitly enabled a cache backend (e.g., RedisCache, SqliteCache, or InMemoryCache passed to StateGraph.compile(cache=...)), and has at least one node configured with CachePolicy.pickle.dumps() with a custom __reduce__ method that spawns a reverse shell or executes a system command.JsonPlusSerializer — specifically as a ("pickle", <base64-encoded-pickle-bytes>) tuple — so that loads_typed() routes it to pickle.loads().redis-cli SET <langgraph-cache-key> <payload>) or write it to the SQLite cache file at the appropriate key.loads_typed() function will call pickle.loads() on the attacker-controlled bytes, executing the embedded payload with the privileges of the LangGraph process (GitHub Advisory, ZDI Advisory).SET commands from unauthorized clients writing to LangGraph cache keyspaces.\x80\x04 or \x80\x05) rather than expected JSON/msgpack content; SQLite cache files modified by unexpected users or processes./bin/sh, bash, curl, wget, python3) not consistent with normal graph execution; unexpected network connections initiated by the LangGraph service account.pickle type entries being processed by JsonPlusSerializer; Redis access logs showing SET operations from unexpected source IPs or service accounts.*.db) in the application's working directory.The primary remediation is to upgrade langgraph-checkpoint to version 4.0.0 or later, which changes the BaseCache default serializer to JsonPlusSerializer(pickle_fallback=False), eliminating the unsafe deserialization path (GitHub Release, Patch PR). If immediate patching is not possible, disable caching entirely by not passing cache=... to StateGraph.compile() or any other BaseCache configuration. Additionally, harden cache backend access controls: enforce strong authentication on Redis instances, restrict network access to cache services, apply strict file permissions on SQLite cache files, and isolate cache infrastructure between tenants. IBM has also released fixes for affected products including IBM Cloud Pak for Business Automation (April 2026 iFixes) and IBM watsonx Orchestrate Developer Edition (IBM CP4BA Advisory, IBM watsonx Advisory).
The vulnerability was credited to researchers Peter Girnus (@gothburz), Demeng Chen, and Brandon Niemczyk from Trend Micro's Zero Day Initiative, who published advisory ZDI-26-135 on March 3, 2026 (ZDI Advisory). Red Hat tracked the issue and IBM issued security bulletins addressing the vulnerability across multiple enterprise products in April–May 2026 (Red Hat CVE, IBM CP4BA Advisory). The fix was straightforward — a one-line change flipping pickle_fallback from True to False — and was merged into the LangGraph main branch on January 12, 2026, prior to public disclosure (Patch PR).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."