THREAT OPS › Threat News › [GHSA] GHSA-2c9q-c2q9-qgqv (medium) — langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
[GHSA] GHSA-2c9q-c2q9-qgqv (medium) — langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
GHSA-2c9q-c2q9-qgqv Severity: medium CVE: CVE-2026-55235
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
## Summary
In affected versions of `langgraph-api` (the LangGraph Server runtime), a run or cron could be created with a relative webhook target. When the server later delivers such a webhook, it routes the request back into the
Indicators of compromise
- CVE-2026-55235cve
Original source: https://github.com/advisories/GHSA-2c9q-c2q9-qgqv