{"data":{"ecosystem":"pypi","name":"langgraph-sdk","url":"https://aisecwatch.com/packages/pypi/langgraph-sdk","latestVersion":"0.4.6","firstReleaseAt":"2024-05-02T18:57:00.967Z","repository":"https://github.com/langchain-ai/langgraph/tree/main/libs/sdk-py","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-05-02T18:57:00.967Z","integratedVersion":"0.1.0","sdks":["langgraph"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:httpx"]},"dependencies":[{"ecosystem":"pypi","name":"langchain-core","versionSpec":"<2,>=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":">=0.25.2","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-protocol","versionSpec":">=0.0.15","scope":"runtime"},{"ecosystem":"pypi","name":"orjson","versionSpec":">=3.11.5","scope":"runtime"},{"ecosystem":"pypi","name":"websockets","versionSpec":"<17,>=14","scope":"runtime"}],"advisories":[{"id":"35386226-4085-4707-8584-ecb2748cbd56","url":"https://aisecwatch.com/issues/35386226-4085-4707-8584-ecb2748cbd56","cveId":"CVE-2026-104873","title":"GHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decorators","headline":null,"severity":"high","publishedAt":"2026-10-05T22:49:35.000Z","affected":["langgraph-sdk@>= 0.1.45, <= 0.4.3 (fixed: 0.4.4)"],"epssScore":0.00253},{"id":"1a7b1d9c-c83f-4d70-8dfc-1dabfc66f364","url":"https://aisecwatch.com/issues/1a7b1d9c-c83f-4d70-8dfc-1dabfc66f364","cveId":"CVE-2026-48776","title":"GHSA-w39p-vh2g-g8g5: LangGraph SDK has unsafe URL path construction","headline":null,"severity":"medium","publishedAt":"2026-06-25T18:32:35.000Z","affected":["langgraph-sdk@< 0.3.15 (fixed: 0.3.15)"],"epssScore":0.00293}],"checkedAt":"2026-10-09T21:51:14.032Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}