Get real-time updates on Telegram
P5Verified
LangGraph SDK custom auth silently ignores actions= on resource decorators
CVE-2026-104873 affects langgraph-sdk. EPSS 0.00253 (percentile 0.15202), scored 2026-10-04. Affected range: >= 0.1.45, <= 0.4.3. Fixed version: 0.4.4.
- CVE
- CVE-2026-104873
- CWE
- CWE-863
- Product
- langgraph-sdk
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00253 · percentile 0.15202 · 2026-10-04
- KEV
- no
Affected products
- langgraph-sdk · >= 0.1.45, <= 0.4.3 · Fixed version: 0.4.4
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-05 23:09:08.830529+00:00 UTC
- GitHub Advisory Database · Source record · observed 2026-10-05 23:10:51.172112+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104873.html