{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/langgraph/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:langchain:langgraph-sdk:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-104873"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["langgraph-sdk (\u003e= 0.1.45, \u003c= 0.4.3)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","cve-2026-104873","python","langgraph"],"_cs_type":"advisory","_cs_vendors":["LangChain"],"content_html":"\u003cp\u003eThe LangGraph SDK (versions 0.1.45 through 0.4.3) contains a critical authorization logic vulnerability identified as CVE-2026-104873. The flaw resides in the SDK's implementation of resource-scoped authorization decorators, specifically \u003ccode\u003e@auth.on.threads\u003c/code\u003e, \u003ccode\u003e@auth.on.assistants\u003c/code\u003e, and \u003ccode\u003e@auth.on.crons\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eWhen developers provide an \u003ccode\u003eactions=\u003c/code\u003e argument to these decorators, the SDK fails to filter actions correctly. Instead of binding the handler only to the specified action, it registers the handler for all actions performed on the resource. Because the framework prioritizes these erroneously registered handlers over fallback authorization mechanisms, security checks intended for restricted actions may be bypassed entirely. If the handler logic does not manually validate the requested action against the user's permissions, an authenticated user may execute unauthorized CRUD operations on resources belonging to other users. This vulnerability primarily impacts Python-based deployments utilizing fine-grained action authorization.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eDeployment of affected versions of \u003ccode\u003elanggraph-sdk\u003c/code\u003e allows for potential privilege escalation and unauthorized access to resources, including threads, assistants, and crons. If a developer assumes that a handler only triggers for specific actions, they may neglect to include action-type validation inside the handler function. In such cases, an authenticated attacker can perform unauthorized read, update, or delete operations on resources they do not own. The severity of the impact depends on the specific logic implemented within the vulnerable decorators.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all deployments of \u003ccode\u003elanggraph-sdk\u003c/code\u003e to version 0.4.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit all instances of \u003ccode\u003e@auth.on.threads\u003c/code\u003e, \u003ccode\u003e@auth.on.assistants\u003c/code\u003e, and \u003ccode\u003e@auth.on.crons\u003c/code\u003e to identify usages of the \u003ccode\u003eactions=\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eUntil patching is completed, verify that all authorization handlers invoked by these decorators explicitly validate the action requested (e.g., check \u003ccode\u003ectx.action\u003c/code\u003e) to ensure security regardless of the registration scope.\u003c/li\u003e\n\u003cli\u003eReview access logs for anomalous resource operations (e.g., unexpected PUT/DELETE requests) that may indicate exploitation of this authorization flaw.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T00:46:56Z","date_published":"2026-10-06T00:46:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-langgraph-auth-bypass/","summary":"An authorization bypass vulnerability in the LangGraph SDK causes the actions= parameter on resource-scoped decorators to be ignored, potentially allowing authenticated users to perform unauthorized operations.","title":"Authorization Bypass in LangGraph SDK Resource Decorators","url":"https://feed.craftedsignal.io/briefs/2026-10-langgraph-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Langgraph","version":"https://jsonfeed.org/version/1.1"}