4 min read
News Brief CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
CVE-2026-55253 lets attackers inject MongoDB operators into LangGraph's checkpoint filters, letting one tenant's agent read another tenant's session memory.
Check Point Research found three CVEs in LangGraph's persistence layer. CVE-2025-67644 SQLi chains with CVE-2026-28277 deserialization to reach RCE.
How malicious content in external data sources can hijack agent behaviour in LangChain, LlamaIndex, and AutoGen-style agents via indirect prompt injection through tool responses.