Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, given another user's thread_id, can execute graph runs against the user's thread, read the user's full checkpoint state, and inject arbitrary messages into the user's conversation history. This vulnerability is fixed in 0.9.7.
CVSS
No CVSS.
References
Configurations
No configuration.
History
14 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-14 16:16
Updated : 2026-05-14 18:13
NVD link : CVE-2026-44504
Mitre link : CVE-2026-44504
CVE.ORG link : CVE-2026-44504
JSON object : View
Products Affected
No product.
