CVE-2026-71433: LangGraph Checkpoint: prefix match leaks cross-tenant data

GHSA-47pj-3jcm-6whg MEDIUM
Published August 6, 2026
CISO Take

LangGraph Checkpoint's Postgres and SQLite savers store hierarchical namespaces as a flattened, dot-joined string and scope reads by simple prefix matching, so an ordinary scoped search or list-namespaces call from one authenticated tenant can also return items belonging to a sibling tenant or user whose namespace happens to share the same leading characters — no crafted input required. With 3,763 downstream dependents, this touches a broad slice of production LangGraph deployments that persist agent/workflow state to a shared checkpoint store, and the impact is confidentiality-only (CVSS 5.3, C:H/I:N/A:N) but can expose another tenant's conversation history, tool outputs, or intermediate agent state. It is not in CISA KEV, has no public exploit or Nuclei template, sits at a low EPSS score (0.00225, CISA SSVC decision TRACK), and requires an already-authenticated low-privileged caller plus high attack complexity — so this is not an emergency patch, but it is a real multi-tenant data-isolation gap that auditors and privacy reviewers will flag. Upgrade langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite to 3.1.1+ during your normal patch cycle, and in the interim audit checkpoint namespace naming for any tenant/user IDs that could share a common string prefix.

Sources: NVD GitHub Advisory EPSS CISA KEV ATLAS

What is the risk?

Medium severity (CVSS 5.3) driven entirely by confidentiality impact — there is no integrity or availability effect. The attack requires PR:L (a valid authenticated account already scoped to the checkpoint store) and AC:H (the exploit depends on namespace naming happening to collide under prefix matching, not attacker-controlled crafted input), which caps real-world exploitability. EPSS is low and CISA's SSVC decision is TRACK (monitor, no urgent action), there's no KEV listing, no public PoC, and no scanner template — so mass exploitation is unlikely. The residual risk is concentrated in multi-tenant SaaS or platform deployments where namespace design (e.g., sequential or prefix-overlapping tenant/user IDs like 'tenant_1' and 'tenant_10') makes collisions plausible rather than theoretical.

How does the attack unfold?

Authenticated access
Adversary holds a valid, low-privileged authenticated account scoped to their own tenant's checkpoint namespace.
AML.T0012
Routine query
Adversary issues an ordinary scoped search or list-namespaces call against the checkpoint store — no crafted or malicious input needed.
Prefix-match leak
The flattened, dot-joined namespace is matched as a simple string prefix, so items from a sibling tenant/user namespace sharing the same leading characters are returned in the results.
AML.T0036
Cross-tenant disclosure
Adversary obtains another tenant's stored agent/conversation state, breaching confidentiality with no integrity or availability impact.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
LangGraph pip < 3.1.1 3.1.1
42.3K 4.0K dependents Pushed 5d ago 84% patched ~13d to patch Full package profile →
LangGraph pip < 3.1.1 3.1.1
42.3K 4.0K dependents Pushed 5d ago 84% patched ~13d to patch Full package profile →

How severe is it?

CVSS 3.1
5.3 / 10
EPSS
0.4%
chance of exploitation in 30 days
Higher than 28% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC High
PR Low
UI None
S Unchanged
C High
I None
A None

What should I do?

1 step
  1. Upgrade langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite to version 3.1.1 or later, where namespace matching is fixed to avoid prefix collisions and metacharacter injection. Until patched, avoid namespace naming schemes where one tenant/user ID could be a string prefix of another (e.g., pad or delimit IDs unambiguously, or better, isolate tenants at the database/schema level rather than relying on logical namespace scoping). Review checkpoint store access logs for scoped searches or list-namespaces calls returning items outside the expected namespace, and audit any multi-tenant LangGraph deployment for evidence of cross-tenant reads prior to patching. No CVE-specific detection signature or scanner exists, so detection relies on application-level logging of checkpoint query results versus expected namespace scope.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Art. 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.7 - Data for AI systems
OWASP LLM Top 10
LLM02 - Sensitive Information Disclosure

Frequently Asked Questions

What is CVE-2026-71433?

LangGraph Checkpoint's Postgres and SQLite savers store hierarchical namespaces as a flattened, dot-joined string and scope reads by simple prefix matching, so an ordinary scoped search or list-namespaces call from one authenticated tenant can also return items belonging to a sibling tenant or user whose namespace happens to share the same leading characters — no crafted input required. With 3,763 downstream dependents, this touches a broad slice of production LangGraph deployments that persist agent/workflow state to a shared checkpoint store, and the impact is confidentiality-only (CVSS 5.3, C:H/I:N/A:N) but can expose another tenant's conversation history, tool outputs, or intermediate agent state. It is not in CISA KEV, has no public exploit or Nuclei template, sits at a low EPSS score (0.00225, CISA SSVC decision TRACK), and requires an already-authenticated low-privileged caller plus high attack complexity — so this is not an emergency patch, but it is a real multi-tenant data-isolation gap that auditors and privacy reviewers will flag. Upgrade langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite to 3.1.1+ during your normal patch cycle, and in the interim audit checkpoint namespace naming for any tenant/user IDs that could share a common string prefix.

Is CVE-2026-71433 actively exploited?

No confirmed active exploitation of CVE-2026-71433 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-71433?

Upgrade langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite to version 3.1.1 or later, where namespace matching is fixed to avoid prefix collisions and metacharacter injection. Until patched, avoid namespace naming schemes where one tenant/user ID could be a string prefix of another (e.g., pad or delimit IDs unambiguously, or better, isolate tenants at the database/schema level rather than relying on logical namespace scoping). Review checkpoint store access logs for scoped searches or list-namespaces calls returning items outside the expected namespace, and audit any multi-tenant LangGraph deployment for evidence of cross-tenant reads prior to patching. No CVE-specific detection signature or scanner exists, so detection relies on application-level logging of checkpoint query results versus expected namespace scope.

What systems are affected by CVE-2026-71433?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, multi-tenant SaaS agent orchestration, conversation/agent state persistence.

What is the CVSS score for CVE-2026-71433?

CVE-2026-71433 has a CVSS v3.1 base score of 5.3 (MEDIUM). The EPSS exploitation probability is 0.36%.

What is the AI security impact?

Affected AI Architectures

agent frameworksmulti-tenant SaaS agent orchestrationconversation/agent state persistence

MITRE ATLAS Techniques

AML.T0012 Valid Accounts
AML.T0036 Data from Information Repositories

Compliance Controls Affected

EU AI Act: Art. 15
ISO 42001: A.7
OWASP LLM Top 10: LLM02

What are the technical details?

Original Advisory

LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string as a simple prefix pattern, so a read scoped to one namespace could also match a sibling namespace whose flattened form shares the same leading characters, or a namespace label containing unescaped pattern metacharacters, allowing an authenticated caller to retrieve stored items belonging to another tenant or user through an ordinary scoped search or list namespaces call, with no crafted input required. This issue is fixed in versions 3.1.1 of langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite.

Exploitation Scenario

A SaaS platform built on LangGraph gives each customer their own agent workflow, persisting execution state to a shared Postgres checkpoint store with namespaces derived from customer/user IDs (e.g., 'acme_corp' and 'acme_corp_beta'). A low-privileged authenticated user of one tenant issues a normal, unmodified scoped search or list-namespaces API call against their own checkpoint namespace. Because the underlying implementation matches namespaces as a simple string prefix rather than a proper hierarchical boundary, the query also returns checkpoint items belonging to the sibling namespace whose flattened name shares the same leading characters — exposing that other tenant's stored conversation history, tool-call results, or intermediate agent state, with no injection, exploit chain, or elevated privileges needed.

Weaknesses (CWE)

CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor: The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • [Architecture and Design] Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Timeline

Published
August 6, 2026
Last Modified
August 7, 2026
First Seen
August 6, 2026

Related Vulnerabilities