Resource Management Flaw in LangGraph Python SDK by LangChain AI
CVE-2026-104873
7.6HIGH
What is CVE-2026-104873?
The LangGraph Python SDK connects applications to LangGraph API servers and manages various resources, including assistants and threads. Versions from 0.1.45 to 0.4.3 contain an authorization flaw in the resource-scoped decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons. This issue arises when the actions argument is ignored, allowing unauthorized access to resources. An authenticated user can potentially read, update, or delete another user's data due to improper handling of resource actions. Protecting a deployment requires that selected handlers enforce the necessary permissions independently. The vulnerability has been addressed in version 0.4.4.
Affected Version(s)
langgraph >= 0.1.45, < 0.4.4
