CVE-2026-25750Disclosure(langchain / langsmith)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch langchain langsmith systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulnerability existed in LangSmith Studio that could allow unauthorized access to user accounts through stolen authentication tokens. The vulnerability affected both LangSmith Cloud and self-hosted deployments. Authenticated LangSmith users who clicked on a specially crafted malicious link would have their bearer token, user ID, and workspace ID transmitted to an attacker-controlled server. With this stolen token, an attacker could impersonate the victim and access any LangSmith resources or perform any actions the user was authorized to perform within their workspace. The attack required social engineering (phishing, malicious links in emails or chat applications) to convince users to click the crafted URL. The stolen tokens expired after 5 minutes, though repeated attacks against the same user were possible if they could be convinced to click malicious links multiple times. The fix in version 0.12.71 implements validation requiring user-defined allowed origins for the baseUrl parameter, preventing tokens from being sent to unauthorized servers. No known workarounds are available. Self-hosted customers must upgrade to the patched version.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langsmith

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-04); latest day: 1
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
langsmith

Deep dive

Activity timeline11 mentions / 7d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-13: 2Mentions · 2026-03-14: 2Mentions · 2026-03-15: 1Mentions · 2026-03-16: 2Mentions · 2026-03-20: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 2Technical Details · 2026-03-16: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-29: 103-0403-1303-1403-1503-1603-2003-29
Signal classification2 categories
Disclosure
654.5%
Patch
545.5%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure1Patch1
2026-03-132
Disclosure2
2026-03-142
Disclosure2
2026-03-151
Patch1
2026-03-162
Disclosure1Patch1
2026-03-201
Patch1
2026-03-291
Patch1
Full discourse11 posts
  • Sekurak@Sekurak
    Patch

    🚨 Wystarczyła manipulacja jednym parametrem żądania, aby przejąć konto w LangSmith. 🛡️ Jeżeli korzystasz z LangSmith do budowy swoich aplikacji AI mamy ważne ostrzeżenie. 💻 Badacze z Miggo Security wykryli poważną lukę bezpieczeństwa (CVE-2026-25750) pozwalającą na przejęcie konta. 🛠️ Źródłem całego zamieszania był parametr baseURL, pozwalający na definicję własnych serwerów backend. Przez brak walidacji danych, przeglądarka użytkownika przesyłała aktywny token sesyjny bezpośrednio na serwer kontrolowany przez atakującego. ✅ Błąd został naprawiony w wersji 0.12.71 LangSmith. Użytkownicy korzystający z architektury chmurowej nie muszą podejmować żadnych działań, poprawka została automatycznie wdrożona. W przypadku rozwiązań self-hosted zalecamy niezwłoczną aktualizację. 👉 Szczegóły: https://sekurak.pl/jak-manipulacja-parametrem-zadania-mogla-doprowadzic-do-przejecia-konta-w-langsmith-szczegoly-podatnosci-cve-2026-25750/

    Post summary

    CVE‑2026‑25750 in LangSmith permits session hijacking via an unsanitized baseURL parameter; the issue was fixed in version 0.12.71, and users—especially self‑hosted deployments—are urged to update immediately.

    0303175.0K
    42.8K followersView on X
  • Audrey Renée Bentley@BentleyAudrey
    Disclosure

    https://api.cyfluencer.com/s/hack-the-ai-brain-uncovering-an-account-takeover-vulnerability-in-langsmith-25937/1 Miggo Security discovered a critical account takeover vulnerability (CVE-2026-25750) in LangSmith. Learn how this flaw exposed proprietary AI data.

    Post summary

    The excerpt announces the discovery of a critical account takeover flaw (CVE‑2026‑25750) in LangSmith, highlighting its potential to expose proprietary AI data.

    0501211.1K
    33.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    LangSmith の脆弱性 CVE-2026-25750 が FIX:API 設定不備とセッション情報の流出 https://iototsecnews.jp/2026/03/14/critical-langsmith-account-takeover-vulnerability-puts-users-at-risk/ LangSmith で見つかった CVE-2026-25750 は、データの取得先を開発者が自由に指定できる、base URL パラメータの仕様に起因します。この機能において、入力された接続先ドメインが正しいものどうかを確認する検証プロセスが欠けていたことで、アプリケーションが外部からの入力値を無条件に信頼してしまうという問題が生じています。 この検証不足により、認証済みのユーザーが細工されたリンクを踏むだけで、ブラウザがセッション認証情報を攻撃者のサーバへ自動送信してしまうリスクが生じています。現在は、許可されたオリジン (信頼できるドメイン) のみを事前登録して制限する対策が取られています。ご利用のチームは、ご注意ください。 #AI #ML #CVE202625750 #LangSmith #Vulnerability

    Post summary

    The post explains CVE-2026-25750 in LangSmith, detailing the flaw and the vendor’s fix that enforces a whitelist of trusted origins, but it offers no PoC, exploit code, or evidence of active exploitation.

    01000173
    484 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    CVSS 8.5 vuln in LangSmith could enable token theft and full account takeover. Extensive info, including fix info, at SecAlerts: CVE-2026-25750, CVSS 8.5: https://secalerts.co/vulnerability/CVE-2026-25750 #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE202625750 #LangSmith https://t.co/6UioUco80I

    Post summary

    The tweet announces a high‑severity vulnerability in LangSmith (CVE‑2026‑25750) that could allow token theft and account takeover, and directs readers to SecAlerts for fix information.

    00010135
    803 followersView on X
  • Ben Rothke@benrothke
    Disclosure

    Critical account takeover vulnerability (CVE-2026-25750) in #LangSmith platform for LLM applications discovered by @MiggoSecurity. They detail how the flaw exposed proprietary AI data. Issue highlights the importance of analyzing complex application logic. https://api.cyfluencer.com/s/hack-the-ai-brain-uncovering-an-account-takeover-vulnerability-in-langsmith-25853

    Post summary

    A critical account takeover CVE (CVE-2026-25750) affecting the LangSmith platform is reported, noting proprietary AI data exposure, but lacking PoC, exploit code, patch information, or active exploitation details.

    0000199
    9.1K followersView on X
  • InfoSecSherpa 🏔️@InfoSecSherpa
    Disclosure

    "Hack the #AI Brain: Uncovering an Account Takeover Vulnerability in LangSmith" Miggo Security discovered a critical account takeover vulnerability (CVE-2026-25750) in LangSmith. Learn how this flaw exposed proprietary AI data. https://api.cyfluencer.com/s/hack-the-ai-brain-uncovering-an-account-takeover-vulnerability-in-langsmith-25858 https://t.co/Rd5i56Lcnh

    Post summary

    The tweet announces the discovery of CVE-2026-25750 as an account takeover flaw in LangSmith, but provides no PoC, exploit, or mitigation details.

    00010280
    51.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25750 Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulner… https://www.cve.org/CVERecord?id=CVE-2026-25750 ----- Traducción: CVE-2026-25750 Lan… http://infoflow.cloud`

    Post summary

    The post announces a CVE-2026-25750 URL parameter injection flaw in older Langchain Helm charts, citing the version affected and linking to the official CVE record.

    0001036
    55 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25750 Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulner… https://www.cve.org/CVERecord?id=CVE-2026-25750

    Post summary

    The announcement highlights a URL parameter injection flaw in older Langchain Helm charts, which was addressed in the 0.12.71 release, providing a clear patch reference.

    00010180
    56.6K followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical vulnerability CVE-2026-25750 in LangSmith exposes users to account takeovers. Immediate updates required to safeguard AI environments. Link: https://thedailytechfeed.com/critical-langsmith-vulnerability-risking-account-takeovers-urgent-update-required/ #Security #Vulnerability #Update #AI #Technology #Software #Privacy #Hacking #Threat #Patch #Bug #Exploit #Network #System #IT #Ransomware #Cyber #Malware #Breach #Defense

    Post summary

    The tweet warns of CVE‑2026‑25750, a critical LangSmith flaw that could lead to account takeovers, and urges users to apply updates immediately to protect their AI environments.

    0000012
    264 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical LangSmith Flaw Could Let Attackers Hijack AI Monitoring Accounts Through Session Token Theft Cyber Press reports that CVE-2026-25750 in LangSmith let attacker-controlled base URLs capture authenticated session credentials, creating a short window for silent account takeover and access to sensitive AI trace data. This matters because compromised LangSmith accounts could expose proprietary prompts, internal query results, customer data, and other high-value enterprise AI telemetry. 🎯 Target: Global/Enterprise AI Environments #️⃣ Category: #Vulnerability #AI_Threats #BlueTeam #CyberIntel 🔗 URL: https://cyberpress.org/critical-langsmith-vulnerability/

    Post summary

    Cyber Press reports CVE-2026-25750 as a session-token theft flaw in LangSmith that could allow attackers to hijack accounts, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000056
    286 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Critical LangSmith Flaw Could Let Attackers Hijack AI Monitoring Accounts Through Session Token Theft Cyber Security News reports that CVE-2026-25750 in LangSmith allowed attacker-controlled base URLs to receive authenticated API requests and session credentials, creating a five-minute window for silent account takeover and access to sensitive AI trace data. This matters because compromised LangSmith accounts could expose proprietary prompts, internal database outputs, customer data, and other high-value enterprise AI telemetry. 🎯 Target: Global/Enterprise AI Environments #️⃣ Category: #Vulnerability #AI_Threats #BlueTeam #CyberIntel 🔗 URL: https://cybersecuritynews.com/critical-langsmith-account-takeover-vulnerability/

    Post summary

    The post announces CVE‑2026‑25750 in LangSmith, explaining how attacker-controlled URLs can hijack session tokens for a limited takeover window, but provides no PoC, patch, or evidence of active exploitation.

    0000053
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangsmith-kubernetes-

Explore more