{"data":{"id":"35386226-4085-4707-8584-ecb2748cbd56","title":"GHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decorators","summary":"langgraph-sdk applies the actions= argument incorrectly on resource-scoped authorization decorators, including @auth.on.threads, @auth.on.assistants, and @auth.on.crons. A handler meant for selected actions is instead registered for every action on the resource, so broader fallback handlers that carry authorization checks may not run. Only Python deployments using actions= on these decorators are affected.","solution":"Patched in 0.4.4. No workaround is documented.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-fvww-7h3r-vfhp","publishedAt":"2026-10-05T22:49:35.000Z","cveId":"CVE-2026-104873","cweIds":["CWE-863"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["langgraph-sdk@>= 0.1.45, <= 0.4.3 (fixed: 0.4.4)"],"affectedPackageNames":["langgraph-sdk"],"affectedPackageRefs":["pypi:langgraph-sdk"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LangGraph SDK","langgraph-sdk"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00253,"epssCheckedAt":"2026-10-10T04:57:18.556Z","kevDateAdded":null,"advisoryAliases":["GHSA-fvww-7h3r-vfhp"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-05T22:49:35.000Z","capecIds":["CAPEC-122"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}