← Back to CVE search

CVE-2026-59152

LangSmith Client SDKs

Description

LangSmith Client SDKs provide SDK-s for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK-s TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a party with workspace trace-read access (for example a low-privilege workspace member, a contractor, or a compromised teammate account) gains the ability to read files from any server running TracingMiddleware, a capability outside that workspace-s intended trust boundary. This vulnerability is fixed in 0.8.18.

CVSS 5EPSS 0.174%Risk 0.51
View source
Published
2026-07-06 16:16:37
Affected versions
< 0.8.18
Type
Library
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N