CVE-2025-8709
Last modified
CVE-2025-8709 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers to inject arbitrary SQL, leading to unauthorized access to all documents, data exfiltration of sensitive fields such as passwords and API keys, and a complete bypass of application-level security filters.
Metrics
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-8709?
How severe is CVE-2025-8709?
How do I fix CVE-2025-8709?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8703A vulnerability classified as critical was found in Wanzhou …8.8
- CVE-2025-8704A vulnerability, which was classified as critical, has been …8.8
- CVE-2025-8705A vulnerability, which was classified as critical, was found…8.8
- CVE-2025-8706A vulnerability has been found in Wanzhou WOES Intelligent O…8.8
- CVE-2025-8707A vulnerability was found in Huuge Box App 1.0.3 on Android.…5.5
- CVE-2025-8708A vulnerability was found in Antabot White-Jotter 0.22. It h…7.5
- CVE-2025-8711CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Iva…5.4
- CVE-2025-8712Missing authorization in Ivanti Connect Secure before 22.7R2…5.4
- CVE-2025-8713PostgreSQL optimizer statistics allow a user to read sampled…3.1
- CVE-2025-8714Untrusted data inclusion in pg_dump in PostgreSQL allows a m…8.8
- CVE-2025-8715Improper neutralization of newlines in pg_dump in PostgreSQL…8.8
- CVE-2025-8716In Content Management versions 20.4- 25.3 authenticated atta…5.8
Are you affected by CVE-2025-8709?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
