THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2c9q-c2q9-qgqv (medium) — langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

[GHSA] GHSA-2c9q-c2q9-qgqv (medium) — langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

medgithub_advisoriesPublished 2026-08-19

GHSA-2c9q-c2q9-qgqv Severity: medium CVE: CVE-2026-55235

langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

## Summary

In affected versions of `langgraph-api` (the LangGraph Server runtime), a run or cron could be created with a relative webhook target. When the server later delivers such a webhook, it routes the request back into the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2c9q-c2q9-qgqv