langsmith vulnerabilities
CVEs whose affected-version data names the langsmith package (npm, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-59152High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
GHSA-f4xh-w4cj-qxq8High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
CVE-2026-45134High· 7.1LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-41182Medium· 5.3LangSmith SDK: Streaming token events bypass output redaction
LangSmith SDK: Streaming token events bypass output redaction
CVE-2026-40190Medium· 5.6LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() …
CVE-2026-25528Medium· 5.8LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection