Langchain-AI / Langsmith-Sdk
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59152 | Arbitrary server-side file read in LangSmith SDK TracingMiddleware | MEDIUM | 5.0 | Jul 6, 2026 |
| CVE-2026-45134 | LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning | HIGH | 7.1 | May 27, 2026 |
| CVE-2026-41182 | LangSmith SDK: Streaming token events bypass output redaction | MEDIUM | 5.3 | Apr 23, 2026 |
| CVE-2026-40190 | LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()` | CRITICAL | 9.8 | Apr 10, 2026 |
| CVE-2026-25528 | LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection | MEDIUM | 5.8 | Feb 9, 2026 |
Showing 1 to 5 of 5 CVEs