Vulnerability library
Security checkJune 08, 2026

LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmlangsmith

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The LangSmith SDK’s prompt pull methods (pull_prompt / pull_prompt_commit in Python, pullPrompt / pullPromptCommit in JS/TS) fetch and deserialize prompt manifests from the LangSmith Hub. These manifests may contain serialized LangChain objects and model configuration that affect runtime behavior.

Recommendation

Update the langsmith package to the latest compatible version. Followings are version details:

  • Affected version(s): < 0.6.0
  • Patched version(s): 0.6.0

References

Could your website be exposed too?

SmartScanner can check your website for LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated June 08, 2026