Junglewise Threat Intelligence

CVE-2026-41182: LangChain LangSmith SDK sensitive information leak in streaming events

CVE-2026-41182 · Severity: medium · CVSS 5.3 · Published 2026-04-23

Technologies: langsmith (PyPI), LangChain LangSmith SDK, langsmith (npm). Vendors: LangChain, PyPI, npm.

Executive brief

LangSmith SDKs are used to monitor and debug Large Language Model (LLM) applications. A flaw in the SDKs' redaction feature allows sensitive information to be leaked to the LangSmith platform even when users have explicitly enabled privacy controls to hide outputs. This occurs because the redaction logic fails to filter data during real-time streaming, potentially exposing private customer data or proprietary information in logs.

Technical details

A vulnerability exists in the LangSmith JavaScript and Python SDKs where output redaction controls (hideOutputs/hide_outputs) are bypassed during LLM streaming. While the SDKs correctly redact the final 'inputs' and 'outputs' fields of a run, they fail to process the 'events' array. During streaming, each chunk is recorded as a 'new_token' event containing the raw token value. Because the redaction pipeline (specifically prepareRunCreateOrUpdateInputs in JS and _hide_run_outputs in Python) does not inspect these events, sensitive data is transmitted to and stored on the LangSmith platform in its raw form. This issue is resolved in JavaScript SDK version 0.5.19 and Python SDK version 0.7.31.

Affected products

  • LangChain langsmith-sdk (Python) <=0.7.30
  • LangChain langsmith (JavaScript/NPM) <=0.5.18

Timeline

  • 2026-04-14: advisory: GitHub Security Advisory published
  • 2026-04-23: disclosed: CVE published to NVD

References

Related threats