vulnerabilityCVE-2026-104873
CVE-2026-104873
A flaw was found in langgraph-sdk. This vulnerability allows an authenticated attacker to bypass authorization controls to access, modify, or delete resources belonging to other users. The issue occurs because resource-scoped authorization decorators fail to restrict handlers to specified actions, inadvertently registering wildcard handlers that override fallback permission and ownership checks.
Exploitation evidence
None confirmed
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action