Vulnerabilities/

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

Severity:
High

Description

The LangSmith SDK’s prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior.

Recommendation

Update the langsmith package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
langsmith
Anything's wrong? Let us know Last updated on June 08, 2026