Impact
The vulnerability resides in the run-creation path of the LangGraph API, where the assistant attached to a run in the assistants.search event. This omission allows a low‑privileged user to reference another user's private assistant by calling POST /runs or POST /threads/{thread_id}/runs. The response can reveal sensitive metadata, configuration, and context of the private assistant, and the run can be executed using that assistant’s configuration, effectively enabling unauthorized execution. The weakness is classified as CWE‑285 because it involves improper authorization checks.
Affected Systems
The issue affects deployments of langchain-ai:langgraph-api prior to version 0.10.0, particularly those that employ custom resource handlers lacking an assistants.search event or a global owner filter. Deployments using the default or a properly configured global ownership filter are not affected, but custom setups that omit the search handler remain vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Attackers with authenticated low‑privileged API access can exploit the missing owner filter during run creation by POST /, enabling them to reference another user's private assistant. They can then read that assistant's metadata, configuration, and context, and trigger a run using the compromised assistant's configuration, potentially leading to unauthorized execution and information disclosure.
OpenCVE Enrichment
Github GHSA