HIGH7.7CVE-2026-59152LangSmith SDK TracingMiddleware: Arbitrary server-side file read from 0, < 0.8.18
HIGH7.1CVE-2026-45134LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning from 0, < 0.8.0
HIGH7.1CVE-2026-45134LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning from 0, < 0.8.0
MEDIUM5.8LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
>= 0.4.10, < 0.6.3
MEDIUM5.8LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
>= 0.4.10, < 0.6.3
MEDIUM5.3LangSmith SDK: Streaming token events bypass output redaction
from 0, < 0.7.31
MEDIUM5.3LangSmith SDK: Streaming token events bypass output redaction
from 0, < 0.7.31