All 5 CVE vulnerabilities found in langsmith-sdk, with AI-generated Chinese analysis, references, and POCs.
Vendor: langchain-ai
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-59152 | Arbitrary server-side file read in LangSmith SDK TracingMiddleware CWE-22 | 5.0 | Medium | 2026-07-06 |
| CVE-2026-45134 | LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning CWE-502 | 7.1 | High | 2026-05-27 |
| CVE-2026-41182 | LangSmith SDK: Streaming token events bypass output redaction CWE-200 | 5.3 | Medium | 2026-04-23 |
| CVE-2026-40190 | LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()` CWE-1321 | 5.6 | Medium | 2026-04-10 |
| CVE-2026-25528 | LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection CWE-918 | 5.8 | Medium | 2026-02-09 |
All 5 known CVE vulnerabilities affecting langsmith-sdk with full Chinese analysis, references, and POCs where available.