LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
Published May 27, 2026
7.1
HIGHCVSS 3.1
EPSS 0.34%
Description
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest content is controlled by an external party, but prior versions of the SDK did not distinguish this from pulling a prompt within the caller's own organization. This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.
Affected products
-
- Version < 0.6.0StatusaffectedConstraints-
- Version < 0.8.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Langchain-AI | Langsmith-Sdk | n/a |
|
No data.
No data.
OpenShift Lightspeed
openshift-lightspeed/lightspeed-service-api-rhel9
Affected
Red Hat Ansible Automation Platform 2
ansible-automation-platform-24/lightspeed-rhel8
Will not fix
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-chatbot-rhel8
Will not fix
Red Hat Ansible Automation Platform 2
ansible-automation-platform-25/lightspeed-rhel8
Will not fix
Red Hat Ansible Automation Platform 2
ansible-automation-platform-26/lightspeed-rhel9
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-llama-stack-core-rhel9
Affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-trustyai-nemo-guardrails-server-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-service-api-rhel9 | Affected | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-24/lightspeed-rhel8 | Will not fix | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-chatbot-rhel8 | Will not fix | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-rhel8 | Will not fix | n/a |
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-llama-stack-core-rhel9 | Affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-trustyai-nemo-guardrails-server-rhel9 | Affected | n/a |
langsmith
PyPI
Introduced 0 Fixed 0.8.0langsmith
npm
Introduced 0 Fixed 0.6.0langchain-classic
PyPI
Introduced 0 Fixed 1.0.7langchain
PyPI
Introduced 0 Fixed 0.3.30
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| PyPI | langsmith | 0 | 0.8.0 |
| npm | langsmith | 0 | 0.6.0 |
| PyPI | langchain-classic | 0 | 1.0.7 |
| PyPI | langchain | 0 | 0.3.30 |
Remediation
Red Hat statement
This Moderate impact vulnerability in LangSmith Client SDKs can lead to information disclosure and potential integrity loss. Red Hat products using these SDKs are affected when pulling public prompts from the LangSmith Hub, as untrusted manifest content may be deserialized. This could result in the execution of malicious LangChain objects or model configurations, requiring user interaction for exploitation.
Red Hat mitigation
To mitigate this vulnerability, avoid pulling public prompts from the LangSmith Hub using the LangSmith Client SDKs without explicit trust. The SDK provides a `dangerously_pull_public_prompt` flag (Python) or `dangerouslyPullPublicPrompt` (JS/TS) that must be set to `True` to enable pulling public prompts by `owner/name`. Do not enable this flag unless the prompt's contents have been independently reviewed and trusted. Additionally, when pulling prompts, avoid setting `include_model=True` or `secrets_from_env=True` if the prompt source is untrusted, as these options expand the deserialization allowlist and allow reading environment variables.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 2, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.34% (0.00344) | 25.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.20% (0.00199) | 9.80th | v5 (v2026.06.15) |
| May 28, 2026 | 0.03% (0.00033) | 10.19th | v4 (v2025.03.14) |
References (6)
- https://access.redhat.com/security/cve/CVE-2026-45134 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2482408 Issue Tracking
- https://github.com/advisories/GHSA-3644-q5cj-c5c7 Advisory
- https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-45134
- https://www.cve.org/CVERecord?id=CVE-2026-45134
Change history (0)
No recorded changes yet.