© 2025-2026 PySpect
First version without a known vulnerability: 3.1.1
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores
Fixed in: 3.1.1
LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method
Fixed in: 3.0.1
LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore
Fixed in: 2.0.11
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
Fixed in: 2.0.11