HighVulnerability
GHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decorators
- Identifiers
- CVE-2026-104873GHSA-fvww-7h3r-vfhp
- Published
- Record updated
- Affected
- langgraph-sdk >= 0.1.45, <= 0.4.3
- Fixed in
- 0.4.4
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
langgraph-sdk applies the actions= argument incorrectly on resource-scoped authorization decorators, including @auth.on.threads, @auth.on.assistants, and @auth.on.crons. A handler meant for selected actions is instead registered for every action on the resource, so broader fallback handlers that carry authorization checks may not run. Only Python deployments using actions= on these decorators are affected.
Mitigation
Patched in 0.4.4. No workaround is documented.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- langgraph-sdkPyPILLM dependency since 2024-05-02 · 3 tracked dependents
Related items
- HighCVE-2026-106119: LangChain MongoDBChatMessageHistory query injection via session identifierSame vendor · NVD/CVE Database
- LowGHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text ValuesSame vendor · GitHub Advisory Database
- HighCVE-2026-72848: SitemapLoader nested sitemap entries bypass restrict_to_same_domainSame vendor · NVD/CVE Database
- HighGHSA-533j-2v4q-mw5h: LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposureSame vendor · GitHub Advisory Database
- MediumGHSA-jfj5-wrj9-63x4: langgraph-api: Incomplete assistant authorization in LangGraph Server run creationSame vendor · GitHub Advisory Database