CVE-2026-59152Disclosure

LOWCVSS 5.0 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a party with workspace trace-read access (for example a low-privilege workspace member, a contractor, or a compromised teammate account) gains the ability to read files from any server running TracingMiddleware, a capability outside that workspace's intended trust boundary. This vulnerability is fixed in 0.8.18.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-346CWE-843

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-06: 2Patch / Workaround · 2026-07-06: 2Technical Details · 2026-07-06: 107-06
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Patch

    CVE-2026-59152 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the Lan… https://www.cve.org/CVERecord?id=CVE-2026-59152

    Post summary

    The CVE affects LangSmith Client SDKs before version 0.8.18; installing version 0.8.18 or later addresses the vulnerability.

    00010994
    57.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-59152 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the Lan… https://www.cve.org/CVERecord?id=CVE-2026-59152 ----- Traducción: CVE-2026-59152 Lan… http://infoflow.cloud`

    Post summary

    The post highlights CVE‑2026‑59152, noting a flaw in LangSmith SDKs before version 0.8.18 that can be triggered via HTTP requests, with an implied mitigation through upgrading past 0.8.18.

    0000041
    92 followersView on X

Explore more