ZERO
Back
vulnerabilityCVE-2026-104873

CVE-2026-104873

A flaw was found in langgraph-sdk. This vulnerability allows an authenticated attacker to bypass authorization controls to access, modify, or delete resources belonging to other users. The issue occurs because resource-scoped authorization decorators fail to restrict handlers to specified actions, inadvertently registering wildcard handlers that override fallback permission and ownership checks.

Exploitation evidence
None confirmed

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action