langgraph-sdk is vulnerable to Incorrect Authorization
76
High Risk
The langgraph-sdk custom authorization layer registers resource scoped handlers incorrectly. When the actions= parameter is passed to decorators @auth.on.threads, @auth.on.assistants, or @auth.on.crons, the handler is registered as a wildcard for every action on the resource instead of only the selected actions. Authenticated users can reach resource operations that the intended scope should have restricted, depending on how the handler is implemented. The fix validates action selectors, rejects invalid or duplicate registrations, and registers handlers only for the explicitly selected actions.
You are affected if you are using a version that falls within the vulnerable range and you pass actions= to resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, or @auth.on.crons in a custom auth configuration.
langgraph-sdk is vulnerable to Incorrect Authorization in versions 0.1.45 - 0.4.3.
Upgrade the langgraph-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.