PT-2026-34593 · Langchain · Langsmith Python Sdk+1

Published

2026-04-16

·

Updated

2026-05-22

·

CVE-2026-41182

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LangSmith JavaScript SDK versions prior to 0.5.19 LangSmith Python SDK versions prior to 0.7.31
Description Output redaction controls do not apply to streaming token events. When a Large Language Model run produces streaming output, each chunk is recorded as a new token event containing the raw token value, which bypasses the redaction pipeline. Specifically, the functions prepareRunCreateOrUpdateInputs() in JavaScript and hide run outputs() in Python only process the inputs and outputs fields on a run and ignore the events array. Consequently, applications using the hideOutputs variable in JavaScript or the hide outputs variable in Python to prevent sensitive data from being stored in LangSmith will still leak full streamed content via run events.
Recommendations Update JavaScript SDK to version 0.5.19. Update Python SDK to version 0.7.31.

Fix

Insertion into Log File

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-41182
GHSA-RR7J-V2Q5-CHGV

Affected Products

Langsmith Javascript Sdk
Langsmith Python Sdk