Three widely-deployed AI agent frameworks contain critical vulnerabilities—path traversal, SQL injection, and unsafe deserialization—enabling remote code execution. Check Point Research found SQL injection in LangGraph’s checkpointer that chains to RCE, with approximately 7,000 exposed Langflow instances under active exploitation since June.