Back

HIGH

LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

Published May 27, 2026

Description

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest content is controlled by an external party, but prior versions of the SDK did not distinguish this from pulling a prompt within the caller's own organization. This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.

Affected products

Remediation

Red Hat statement

This Moderate impact vulnerability in LangSmith Client SDKs can lead to information disclosure and potential integrity loss. Red Hat products using these SDKs are affected when pulling public prompts from the LangSmith Hub, as untrusted manifest content may be deserialized. This could result in the execution of malicious LangChain objects or model configurations, requiring user interaction for exploitation.

Red Hat mitigation

To mitigate this vulnerability, avoid pulling public prompts from the LangSmith Hub using the LangSmith Client SDKs without explicit trust. The SDK provides a `dangerously_pull_public_prompt` flag (Python) or `dangerouslyPullPublicPrompt` (JS/TS) that must be set to `True` to enable pulling public prompts by `owner/name`. Do not enable this flag unless the prompt's contents have been independently reviewed and trusted. Additionally, when pulling prompts, avoid setting `include_model=True` or `secrets_from_env=True` if the prompt source is untrusted, as these options expand the deserialization allowlist and allow reading environment variables.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 27, 2026
Updated Jun 2, 2026
Reserved May 8, 2026
CISA Vulnrichment
Updated Jun 2, 2026
NVD
Status Awaiting Analysis
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 27, 2026
GHSA-3644-Q5CJ-C5C7