Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/langsmith — 4 CVEs · VulnScope
pkg:npm/
langsmith
4 total CVEs
HIGH
1
MEDIUM
3
✅ Check your installed version
Check
All known vulnerabilities
HIGH
7.1
CVE-2026-45134
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
from 0, < 0.6.0
MEDIUM
5.8
CVE-2026-25528
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
>= 0.3.41, < 0.4.6
MEDIUM
5.6
CVE-2026-40190
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
from 0, < 0.5.18
MEDIUM
5.3
LangSmith SDK: Streaming token events bypass output redaction
from 0, < 0.5.19
CVE-2026-41182