SCA: security update for langgraph-checkpoint-postgres, langgraph-checkpoint-sqlite (GHSA-47pj-3jcm-6whg)

medium Tenable Cloud Security Plugin ID 445784

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of
LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-
sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that
string as a simple prefix pattern, so a read scoped to one namespace could also match a sibling namespace
whose flattened form shares the same leading characters, or a namespace label containing unescaped pattern
metacharacters, allowing an authenticated caller to retrieve stored items belonging to another tenant or
user through an ordinary scoped search or list namespaces call, with no crafted input required. This issue
is fixed in versions 3.1.1 of langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite.
(CVE-2026-71433)

Solution

Update the langgraph-checkpoint-postgres library and its related packages to version 3.1.1 or later.

See Also

https://github.com/advisories/GHSA-47pj-3jcm-6whg

Plugin Details

Severity: Medium

ID: 445784

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/7/2026

Updated: 8/7/2026

Risk Information

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4.9

Temporal Score: 3.6

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-71433

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 8/6/2026

Reference Information

CVE: CVE-2026-71433