Executive brief
A vulnerability in the LangGraph library, used for building AI agents, could allow an attacker to bypass security filters or access incorrect data. The issue stems from how the system caches task results, where different inputs (such as different images or data arrays) might be mistakenly treated as identical. This could lead to a situation where a malicious request receives a cached response intended for a benign request, potentially bypassing content moderation or causing data mix-ups.
Technical details
A weak hash vulnerability exists in the `_freeze` function within `libs/langgraph/langgraph/_internal/_cache.py` of LangGraph up to 1.2.4. The `default_cache_key` implementation reduces non-hashable objects exposing a `.tobytes()` method (such as numpy arrays or PIL images) to a tuple containing only the type name, raw bytes, and shape, omitting critical metadata like `dtype`, `mode`, or `palette`. An attacker can exploit this by crafting distinct inputs that share identical raw bytes but different semantic metadata, leading to cache collisions. This allows for moderation bypass or cross-request result reuse in multi-user environments. The attack requires the functional API to be used with keyword arguments and has a high complexity due to the specific input requirements. A fix has been proposed in pull request #8069.
Affected products
- langchain-ai langgraph up to 1.2.4
Timeline
- 2026-06-05: disclosed: Issue reported on GitHub
- 2026-06-13: other: Fix proposed via Pull Request #8069
- 2026-07-05: advisory: NVD/VulDB advisory published