langsmith has 5 CVEs on record. The median CVSS is 7.1 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-f4xh-w4cj-qxq8High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read42CVE-2026-59152High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read42CVE-2026-45134High· 7.1LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning39CVE-2026-25528Medium· 5.8LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection32CVE-2026-41182Medium· 5.3LangSmith SDK: Streaming token events bypass output redaction29
langsmith vulnerabilities
CVEs affecting langsmith, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-59152High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
▾ Twilightlangsmith · langsmithEPSS 0.20%via OSV
GHSA-f4xh-w4cj-qxq8High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
▾ Twilightlangsmith · langsmithvia GHSA
CVE-2026-45134High· 7.1LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
▾ Twilightlangsmith · langsmithEPSS 0.20%via OSV
CVE-2026-41182Medium· 5.3LangSmith SDK: Streaming token events bypass output redaction
LangSmith SDK: Streaming token events bypass output redaction
▾ Sunlitlangsmith · langsmithEPSS 0.21%via OSV
CVE-2026-25528Medium· 5.8LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
▾ Sunlitlangsmith · langsmithEPSS 0.29%via OSV