Description
langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the authentication middleware treats that transport as internal without applying the authentication context used for external requests. In deployments that rely on per-user authorization to separate threads and runs, an authenticated user can direct a webhook to the server's own thread and run routes, allowing creation of a run on or modification of another user's thread and limited incorporation of the targeted thread's metadata into the created run record. The affected path requires webhook targets and per-user authorization boundaries; deployments that deliberately re-enable loopback delivery should restrict it to controlled same-process routes because those webhooks remain unauthenticated. This issue is fixed in version 0.10.0.
Published: 2026-09-14
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass enabling unauthorized in‑process route access
Action: Patch Now
AI Analysis

Impact

A relative webhook target supplied to langgraph-api can be looped back into the server’s own process using an in‑process transport. Because the authentication middleware treats that transport as internal, the request bypasses the normal per‑user authentication context. An attacker who can submit such a webhook can create or modify runs in other users’ threads and inject the targeted thread’s metadata into the forged run, thereby compromising confidentiality and integrity of those user workloads. The flaw does not affect system availability but allows cross‑user data manipulation. This issue is fixed in langgraph-api version 0.10.0.

Affected Systems

The issue exists in the langchain‑ai langgraph‑api component for all releases before 0.10.0. Deployments that rely on per‑user authorization for separate threads and runs are affected loopback same‑process routes.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack is plausible in environments where a user can submit webhooks, as it requires knowledge of the server’s internal routing but does not demand elevated privileges or external network access. An adversary could therefore exploit the vulnerability and affect other users’ runs.

Generated by OpenCVE AI on September 20, 2026 at 23:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade langgraph‑api to version 0.10.0 or later, which removes the loopback transport without authentication.
  • If an upgrade is impractical, disable loopback webhook delivery or limit it strictly to trusted, same‑process routes.
  • Validate and whitelist internal webhook targets so that only explicitly authorized endpoints can be reached, thereby mitigating the authentication bypass.

Generated by OpenCVE AI on September 20, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-2c9q-c2q9-qgqv langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the authentication middleware treats that transport as internal without applying the authentication context used for external requests. In deployments that rely on per-user authorization to separate threads and runs, an authenticated user can direct a webhook to the server's own thread and run routes, allowing creation of a run on or modification of another user's thread and limited incorporation of the targeted thread's metadata into the created run record. The affected path requires webhook targets and per-user authorization boundaries; deployments that deliberately re-enable loopback delivery should restrict it to controlled same-process routes because those webhooks remain unauthenticated. This issue is fixed in version 0.10.0.
Title langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:14:55.630Z

Reserved: 2026-06-16T16:44:00.623Z

Link: CVE-2026-55235

cve-icon Vulnrichment

Updated: 2026-09-16T15:14:51.614Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:12.513

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:00:08Z

Weaknesses