CVE-2026-104873: LangGraph SDK custom auth silently ignores actions= on resource decorators

Published Oct 2, 2026
·
Updated

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and register the selected handler for every action on the resource. Because that wildcard resource handler is selected before broader fallback handlers, an authenticated user may bypass fallback action, ownership, or permission checks and read, update, or delete another user's resource. Only Python deployments using actions on the affected decorators are vulnerable, and a deployment remains protected when the selected handler independently enforces all required checks for every action it receives. This issue is fixed in version 0.4.4.

Affected Software

1 affected component
pypi/langgraph-sdk>=0.1.45<0.4.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade LangGraph Python SDK to a version that resolves this vulnerability.

    Fixed in 0.4.4

Event History

Oct 2, 2026
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are actually vulnerable?

Only Python deployments using langgraph-sdk versions from 0.1.45 until 0.4.4 that pass an actions argument to @auth.on.threads, @auth.on.assistants, or @auth.on.crons are affected. Deployments remain protected if the handler selected by these decorators independently enforces every required check for every action it receives.

2

What access does an attacker need?

An attacker needs to be authenticated. They may be able to read, update, or delete another user's thread, assistant, or cron resource when a broader fallback handler was expected to enforce action, ownership, or permission checks.

3

Why can fallback authorization checks be bypassed?

The affected decorators ignore the actions argument and register the handler for every action on that resource. This wildcard resource handler is selected before broader fallback handlers, preventing those fallback checks from running.

4

What should be done if an immediate upgrade is not possible?

Review handlers registered with the affected resource decorators and ensure each selected handler enforces all required action, ownership, and permission checks itself. Do not rely on broader fallback handlers to apply those checks when actions is used on these decorators.

5

What version fixes the issue?

The issue is fixed in langgraph-sdk version 0.4.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203