CVE-2026-104873: high-severity vulnerability in langchain-ai langgraph
LangGraph SDK custom auth silently ignores actions= on resource decorators
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.6epss 0.3%
exploitation probability
0.3%top 85% of all CVEs
observed exploitation
nono source reports it
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and register the selected handler for every action on the resource. Because that wildcard resource handler is selected before broader fallback handlers, an authenticated user may bypass fallback action, ownership, or permission checks and read, update, or delete another user's resource. Only Python deployments using actions on the affected decorators are vulnerable, and a deployment remains protected when the selected handler independently enforces all required checks for every action it receives. This issue is fixed in version 0.4.4.
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
langchain-ai · langgraphRelated CVEs — langchain-ai langgraph
In the same product, most dangerous first.
CVE-2025-67644HIGHLangGraph SQLite Checkpoint is vulnerable to SQL Injection via metadata filter key in checkpointer list methodEPSS 2.3%CVE-2025-64439HIGHLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializerEPSS 0.9%CVE-2026-28277MEDIUMLangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loadingEPSS 0.7%CVE-2026-48775MEDIUMLangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loadingEPSS 0.7%CVE-2026-71433MEDIUMLangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite storesEPSS 0.4%CVE-2026-14742LOWlangchain-ai langgraph Task Result Cache _cache.py _freeze weak hashEPSS 0.2%