HIGH7.7PyPI
GHSA-f4xh-w4cj-qxq8· CVE-2026-59152LangSmith SDK TracingMiddleware: Arbitrary server-side file read
Modified: 9/10/2026
package
pkg:pypi/langsmith
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
Modified: 9/10/2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
Modified: 9/10/2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
Modified: 7/13/2026
LangSmith SDK: Streaming token events bypass output redaction
Modified: 7/13/2026
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
Modified: 7/13/2026
LangSmith SDK: Streaming token events bypass output redaction
Modified: 9/10/2026
LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
Modified: 9/10/2026