langchain-classic
The agent engineering platform.
Activity
- Latest release
- 3mo ago
- Total releases
- 10
- Cadence
- ~17 days
- Last 12 months
- 10
Reach
- Stars
- 146.2k
Details
- License
- MIT
- First release
- Oct 07, 2025
| Version | Released | |
|---|---|---|
1.0.8
patch
| ||
1.0.7
patch
| ||
1.0.6
patch
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.5
patch
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.4
patch
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.3
patch
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
initial
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0a1
pre
1 CVE
CVE-2026-45134
PYSEC-2026-2560
GHSA-3644-q5cj-c5c7
PYSEC-2026-2555
PYSEC-2026-2582
Jul 13, 2026
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
7.1
/ 10
High
Network
Low
None
Required
Unchanged
High
Low
None
DescriptionThe LangSmith SDK's prompt pull methods ( Prompt manifests can intentionally configure a model with a custom base URL, default headers, model name, or other constructor arguments. These are supported features, but they also mean the prompt contents should be treated as executable configuration rather than plain text. A prompt can also include serialized LangChain
Applications that only pull prompts from their own organization (referenced by name only, without an ImpactAn attacker who publishes a malicious prompt to LangSmith Hub may be able to affect applications that pull that prompt by Realistic impacts include:
RemediationThe LangSmith SDK now blocks pulling public prompts by Upgrade to LangSmith SDK Python >= 0.8.0 or JS/TS >= 0.6.0. Guidance for prompt pull methodsThe prompt pull methods ( When pulling prompts that include model configuration ( Avoid passing Same-organization promptsPrompts pulled from the caller's own organization (referenced by name only, without an The security of same-organization prompts follows a shared responsibility model. The LangSmith SDK enforces trust boundaries for public prompts pulled from external accounts, but it cannot protect against compromised credentials or accounts within the caller's own organization. Securing API keys, managing team member access, and reviewing prompt contents before production deployment are the responsibility of the organization. Organizations should treat prompts as executable configuration and apply the same review and audit practices they would apply to application code. CreditsFirst reported by @Moaaz-0x. Affected versions
1.0.0
1.0.0a1
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
Fixed in
1.0.7
References Updated Jul 13, 2026 · Source: OSV.dev |