PT-2026-23069 · Unknown+1 · Kubernetes+2
Liad-Miggo
·
Published
2026-03-04
·
Updated
2026-03-16
·
CVE-2026-25750
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Langchain Helm Charts versions prior to 0.12.71
Description
Langchain Helm Charts, used for deploying Langchain applications on Kubernetes, had a flaw where a specially crafted link could lead to the theft of authentication tokens. This allowed an attacker to impersonate a user and gain access to LangSmith resources. The attack required convincing a user to click a malicious link, transmitting their bearer token, user ID, and workspace ID to an attacker-controlled server. The stolen tokens were valid for approximately 5 minutes. The issue affected both LangSmith Cloud and self-hosted deployments. The vulnerability stemmed from a lack of validation of the
baseUrl parameter, allowing tokens to be sent to unauthorized servers.Recommendations
Upgrade to version 0.12.71 or later to implement validation requiring user-defined allowed origins for the
baseUrl parameter.Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubernetes
Langsmith
Langchain Helm Charts