INTEL_REPORT
Check Point Research · published 6/11/2026, 1:37:11 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
From SQLi to RCE – Exploiting LangGraph’s Checkpointer By Yarden Porat AI agents need memory. Frameworks like LangGraph provide it through checkpointers – persistence layers that store execution state. But what happens when that persistence layer isn’t locked down? Key Points Background LangGraph is an open-source framework for building stateful, multi-agent AI systems with built-in persistence. It’s an extension of LangChain, with over […] The post F…
https://research.checkpoint.com/2026/from-sqli-to-rce-exploiting-langgraphs-checkpointer
sha256:6071cd795c457b8cc13c42982c6ddda1e31ad54acafe3f2fb5fdead0dc6a35e9
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| pwned.txt |
| Open → |
| domain | os.system | Open → |
| domain | self.checkpointer.list | Open → |
| cve | CVE-2025-67644 | Open → |
| cve | CVE-2026-28277 | Open → |
| cve | CVE-2026-27022 | Open → |
| cve | CVE-2026-28227 | Open → |