Junglewise Threat Intelligence

CVE-2026-48776: LangChain LangGraph SDK path traversal in URL construction

CVE-2026-48776 · Severity: medium · CVSS 4.2 · Published 2026-06-17

Technologies: langgraph (PyPI). Vendors: PyPI, LangChain.

Executive brief

The LangGraph SDK, used for building agentic workflows, contains a vulnerability where it fails to properly clean user-provided identifiers before using them in web addresses. This could allow an attacker to manipulate the SDK into accessing, modifying, or deleting data they shouldn't have access to. The risk is highest for applications that pass raw user input directly to the SDK and rely on external security filters like firewalls that might be bypassed by this manipulation.

Technical details

The langgraph-sdk (Python) constructs HTTP request paths by interpolating caller-supplied identifier values into URL templates without proper path-segment encoding. An attacker providing identifiers containing special characters (e.g., '../' or other URL-significant characters) can cause the SDK to address a different resource or resource type than intended. This is classified as a path traversal (CWE-22) and incorrect authorization (CWE-863) issue. It is particularly exploitable when upstream security layers (WAFs, reverse proxies) perform authorization based on the intended URL prefix, which may differ from the final path delivered to the backend. The vulnerability is fixed in version 0.3.15 by applying proper path-segment encoding.

Affected products

  • LangChain langgraph-sdk < 0.3.15

Timeline

  • 2026-05-22: disclosed: Initial publication to langchain-ai/langgraph
  • 2026-06-17: advisory: Published to NVD
  • 2026-06-25: patched: GitHub Advisory reviewed and updated with patch information

References

Related threats