CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-28277: Unsafe Deserialization in LangGraph

June 25, 2026

An unsafe msgpack deserialization vulnerability in LangGraph that can be exploited to trigger object reconstruction when a checkpoint is loaded by an attacker with checkpoint data modification capabilities, enabling remote code execution.