CVE-2026-104873: LangGraph SDK custom auth silently ignores actions= on resource decorators
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and register the selected handler for every action on the resource. Because that wildcard resource handler is selected before broader fallback handlers, an authenticated user may bypass fallback action, ownership, or permission checks and read, update, or delete another user's resource. Only Python deployments using actions on the affected decorators are vulnerable, and a deployment remains protected when the selected handler independently enforces all required checks for every action it receives. This issue is fixed in version 0.4.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
LangGraph Python SDKto a version that resolves this vulnerability.Fixed in 0.4.4
Event History
Frequently Asked Questions
Which deployments are actually vulnerable?
Only Python deployments using langgraph-sdk versions from 0.1.45 until 0.4.4 that pass an actions argument to @auth.on.threads, @auth.on.assistants, or @auth.on.crons are affected. Deployments remain protected if the handler selected by these decorators independently enforces every required check for every action it receives.
What access does an attacker need?
An attacker needs to be authenticated. They may be able to read, update, or delete another user's thread, assistant, or cron resource when a broader fallback handler was expected to enforce action, ownership, or permission checks.
Why can fallback authorization checks be bypassed?
The affected decorators ignore the actions argument and register the handler for every action on that resource. This wildcard resource handler is selected before broader fallback handlers, preventing those fallback checks from running.
What should be done if an immediate upgrade is not possible?
Review handlers registered with the affected resource decorators and ensure each selected handler enforces all required action, ownership, and permission checks itself. Do not rely on broader fallback handlers to apply those checks when actions is used on these decorators.
What version fixes the issue?
The issue is fixed in langgraph-sdk version 0.4.4.