Impact
A relative webhook target supplied to langgraph-api can be looped back into the server’s own process using an in‑process transport. Because the authentication middleware treats that transport as internal, the request bypasses the normal per‑user authentication context. An attacker who can submit such a webhook can create or modify runs in other users’ threads and inject the targeted thread’s metadata into the forged run, thereby compromising confidentiality and integrity of those user workloads. The flaw does not affect system availability but allows cross‑user data manipulation. This issue is fixed in langgraph-api version 0.10.0.
Affected Systems
The issue exists in the langchain‑ai langgraph‑api component for all releases before 0.10.0. Deployments that rely on per‑user authorization for separate threads and runs are affected loopback same‑process routes.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack is plausible in environments where a user can submit webhooks, as it requires knowledge of the server’s internal routing but does not demand elevated privileges or external network access. An adversary could therefore exploit the vulnerability and affect other users’ runs.
OpenCVE Enrichment
Github GHSA