VendorsLangChainlangsmithall versions
Vulnerabilities

LangChain Langsmith Helm Chart

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-40190
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
Published 2026-04-10 · Analyzed
9.8EPSS 0.004
CVE-2026-25750
LangSmith Studio has URL Parameter Injection Vulnerability that Enables Token Theft via Malicious baseUrl
Published 2026-03-04 · Analyzed
8.5EPSS 0.004