Vulnerabilities/

LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection

Severity:
Medium

Description

The LangSmith SDK’s distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints.


Recommendation

Update the langsmith package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
langsmith
Anything's wrong? Let us know Last updated on February 09, 2026