LangSmith SDK: Streaming token events bypass output redaction
Published Apr 23, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.36%
Description
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely — prepareRunCreateOrUpdateInputs (JS) and _hide_run_outputs (Python) only process the inputs and outputs fields on a run, never the events array. As a result, applications relying on output redaction to prevent sensitive LLM output from being stored in LangSmith will still leak the full streamed content via run events. Version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK fix the issue.
Affected products
-
- Version < 0.5.19StatusaffectedConstraints-
- Version < 0.7.31StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Langchain-AI | Langsmith-Sdk | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
langsmith
npm
Introduced 0 Fixed 0.5.19langsmith
PyPI
Introduced 0 Fixed 0.7.31
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | langsmith | 0 | 0.5.19 |
| PyPI | langsmith | 0 | 0.7.31 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 23, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.36% (0.00358) | 27.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.21% (0.00214) | 11.65th | v5 (v2026.06.15) |
| Apr 23, 2026 | 0.03% (0.00028) | 7.90th | v4 (v2025.03.14) |
References (3)
- https://github.com/advisories/GHSA-rr7j-v2q5-chgv Advisory
- https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-rr7j-v2q5-chgv x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-41182
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-rr7j-v2q5-chgv | Advisory | |
| https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-rr7j-v2q5-chgv | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41182 |
Change history (0)
No recorded changes yet.