Description
The LangSmith SDK’s output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value.
Recommendation
Update the langsmith package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.5.18
- Patched version(s): 0.5.19
References
Could your website be exposed too?
SmartScanner can check your website for LangSmith SDK: Streaming token events bypass output redaction and gives you actionable findings to investigate.
Start a free scanRelated Issues
- LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection - CVE-2026-25528
- LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning - CVE-2026-45134
- LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set( - CVE-2026-40190
- Official Clerk JavaScript SDKs: Middleware-based route protection bypass - @clerk/nextjs - CVE-2026-41248


