{"id":"CVE-2026-45134","aliases":["GHSA-3644-q5cj-c5c7","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"url":"https://o3.security/vulnerability/CVE-2026-45134","summary":"LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","details":"LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior. When pulling a public prompt by owner/name identifier, the manifest content is controlled by an external party, but prior versions of the SDK did not distinguish this from pulling a prompt within the caller's own organization. This vulnerability is fixed in LangSmith SDK Python 0.8.0 and JS/TS 0.6.0.","published":"2026-05-27T19:35:32.662Z","modified":"2026-08-07T11:31:23.771823203Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"langsmith","fixedVersion":"0.6.0"},{"ecosystem":"PyPI","name":"langsmith","fixedVersion":"0.8.0"},{"ecosystem":"PyPI","name":"langchain-classic","fixedVersion":"1.0.7"},{"ecosystem":"PyPI","name":"langchain","fixedVersion":"0.3.30"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45134.json"},{"type":"ADVISORY","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45134"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:23.771823203Z"}}