langgraph-api 实现了 LangGraph API,用于快速开发和测试。在 0.10.0 之前的版本中,langgraph-api 允许某个运行(run)或定时任务(cron)指定一个相对路径的 Webhook 目标,并通过进程内回环传输(in-process loopback transport)进行交付。认证中间件将该传输方式视为内部通道,因此未对其应用与外部请求相同的认证上下文。 在依赖“按用户授权”来隔离线程(threads)和运行(runs)的部署环境中,一个已认证用户可以将 Webhook
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langchain-ai | langgraph-api | < 0.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55253 | 7.7 HIGH | LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant |
| CVE-2026-55236 | 5.9 MEDIUM | langgraph-api: Incomplete assistant authorization in LangGraph Server run creation |
No comments yet