Incorrect Authorization Affecting langgraph-checkpoint-sqlite package, versions [,3.1.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.23% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-LANGGRAPHCHECKPOINTSQLITE-18592347
  • published8 Aug 2026
  • disclosed6 Aug 2026
  • creditUnknown

Introduced: 6 Aug 2026

NewCVE-2026-71433  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade langgraph-checkpoint-sqlite to version 3.1.1 or higher.

Overview

langgraph-checkpoint-sqlite is a Library with a SQLite implementation of LangGraph checkpoint saver.

Affected versions of this package are vulnerable to Incorrect Authorization in the search or list_namespaces process. An attacker can access data from unintended namespaces by crafting namespace labels that share prefixes or include pattern metacharacters, leading to disclosure of items outside the intended scope. This is only exploitable if the application uses namespace labels where one is a prefix of another or contains unescaped pattern characters such as '_' or '%', and relies on namespaces to separate data between users or tenants.

CVSS Base Scores

version 4.0
version 3.1