CVE Explorer
CVE-2026-41182
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. When an LLM run produces streaming output, each chunk is recorded as a new_token event containing the raw token value. These events bypass the redaction pipeline entirely — prepareRunCreateOrUpdateInputs (
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-359","description":"CWE-359: Exposure of Private Personal Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-532","description":"CWE-532: Insertion of Sensitive Information into Log File","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"langsmith-sdk","vendor":"langchain-ai","versions":[{"status":"affected","version":"< 0.5.19"},{"status":"affected","version":"< 0.7.31"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-359","description":"CWE-359: Exposure of Private Personal Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-532","description":"CWE-532: Insertion of Sensitive Information into Log File","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-rr7j-v2q5-chgv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-rr7j-v2q5-chgv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:485950185c1f5eb6c513cea9d18bbbab5790a240e1fcec16d0e1b29083e34ba9 · sha256:cdf632dfb289d855… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.