<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Langgraph - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/langgraph/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:46:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/langgraph/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in LangGraph SDK Resource Decorators</title><link>https://feed.craftedsignal.io/briefs/2026-10-langgraph-auth-bypass/</link><pubDate>Tue, 06 Oct 2026 00:46:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-langgraph-auth-bypass/</guid><description>An authorization bypass vulnerability in the LangGraph SDK causes the actions= parameter on resource-scoped decorators to be ignored, potentially allowing authenticated users to perform unauthorized operations.</description><content:encoded><![CDATA[<p>The LangGraph SDK (versions 0.1.45 through 0.4.3) contains a critical authorization logic vulnerability identified as CVE-2026-104873. The flaw resides in the SDK's implementation of resource-scoped authorization decorators, specifically <code>@auth.on.threads</code>, <code>@auth.on.assistants</code>, and <code>@auth.on.crons</code>.</p>
<p>When developers provide an <code>actions=</code> argument to these decorators, the SDK fails to filter actions correctly. Instead of binding the handler only to the specified action, it registers the handler for all actions performed on the resource. Because the framework prioritizes these erroneously registered handlers over fallback authorization mechanisms, security checks intended for restricted actions may be bypassed entirely. If the handler logic does not manually validate the requested action against the user's permissions, an authenticated user may execute unauthorized CRUD operations on resources belonging to other users. This vulnerability primarily impacts Python-based deployments utilizing fine-grained action authorization.</p>
<h2 id="impact">Impact</h2>
<p>Deployment of affected versions of <code>langgraph-sdk</code> allows for potential privilege escalation and unauthorized access to resources, including threads, assistants, and crons. If a developer assumes that a handler only triggers for specific actions, they may neglect to include action-type validation inside the handler function. In such cases, an authenticated attacker can perform unauthorized read, update, or delete operations on resources they do not own. The severity of the impact depends on the specific logic implemented within the vulnerable decorators.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all deployments of <code>langgraph-sdk</code> to version 0.4.4 or later immediately.</li>
<li>Audit all instances of <code>@auth.on.threads</code>, <code>@auth.on.assistants</code>, and <code>@auth.on.crons</code> to identify usages of the <code>actions=</code> parameter.</li>
<li>Until patching is completed, verify that all authorization handlers invoked by these decorators explicitly validate the action requested (e.g., check <code>ctx.action</code>) to ensure security regardless of the registration scope.</li>
<li>Review access logs for anomalous resource operations (e.g., unexpected PUT/DELETE requests) that may indicate exploitation of this authorization flaw.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>cve-2026-104873</category><category>python</category><category>langgraph</category></item></channel></rss>