-
Type:
Task
-
Resolution: Fixed
-
Priority:
Critical - P2
-
Affects Version/s: None
-
Component/s: AI/ML
-
None
Context
A high risk security vulnerability was found in langgraph-checkpoint's fallback serializer, "JsonSerializer". It is described in detail here: RCE in json mode of JsonPlusSerializer.
Definition of done
- Update minimum requirements of langgraph-checkpoint to 3.0.
- Investigate whether any further changes need to be made [done]. See linked ticket.
- Create test of case described in CVE description.
- Release ASAP.
Pitfalls
What should the implementer watch out for? What are the risks?
- is related to
-
INTPYTHON-826 [LangGraph] Upgrade API used for serialization to allow input of allowed_json_modules
-
- Closed
-