Skip to content
HighVulnerability

GHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decorators

Published
Record updated
View JSON
Affected
  • langgraph-sdk >= 0.1.45, <= 0.4.3
Fixed in
0.4.4
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

langgraph-sdk applies the actions= argument incorrectly on resource-scoped authorization decorators, including @auth.on.threads, @auth.on.assistants, and @auth.on.crons. A handler meant for selected actions is instead registered for every action on the resource, so broader fallback handlers that carry authorization checks may not run. Only Python deployments using actions= on these decorators are affected.

Mitigation

Patched in 0.4.4. No workaround is documented.