Vulnerability Description
langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the authentication middleware treats that transport as internal without applying the authentication context used for external requests. In deployments that rely on per-user authorization to separate threads and runs, an authenticated user can direct a webhook to the server's own thread and run routes, allowing creation of a run on or modification of another user's thread and limited incorporation of the targeted thread's metadata into the created run record. The affected path requires webhook targets and per-user authorization boundaries; deployments that deliberately re-enable loopback delivery should restrict it to controlled same-process routes because those webhooks remain unauthenticated. This issue is fixed in version 0.10.0.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/langchain-ai/docs/blob/7b70fbacab21f84d9c6f9848f86cdeb471adbb
- https://github.com/langchain-ai/helm/security/advisories/GHSA-2c9q-c2q9-qgqv
FAQ
What is CVE-2026-55235?
CVE-2026-55235 is a vulnerability with a CVSS score of 5.9 (MEDIUM). langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-...
How severe is CVE-2026-55235?
CVE-2026-55235 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-55235?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.