Opening SecureFlowLangGraph Checkpointer SQLi and Deserialization RCE
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Check Point Research aidefend-sf0016

LangGraph Checkpointer SQLi and Deserialization RCE

  • Autonomous Agents
  • System Compromise & RCE
  • Model Poisoning & Integrity

Check Point Research demonstrated a chain from a user-controlled LangGraph SQLite checkpointer filter key to a UNION-returned fake checkpoint row and unsafe MsgPack reconstruction. LangGraph's own advisory describes the deserialization issue as a defense-in-depth flaw normally requiring privileged checkpoint-store write access and says it knows of no practical path in existing deployments; the graph retains that disagreement explicitly. A Redis injection issue is parallel and is not connected to the SQLite RCE chain.

Mapped threat techniques

Source