Executive brief
LangSmith SDK is a Python and JavaScript library used to fetch and manage AI prompts from LangSmith Hub. When pulling prompts published by other users, the SDK deserializes untrusted prompt manifests without warning, allowing an attacker to inject malicious code or redirect AI model traffic to attacker-controlled servers. This can lead to credential theft, prompt injection attacks, and service disruption for applications that use public prompts.
Technical details
The vulnerability exists in the pull_prompt / pull_prompt_commit (Python) and pullPrompt / pullPromptCommit (JS/TS) methods, which fetch and deserialize prompt manifests from LangSmith Hub. Prior to the fix, the SDK did not distinguish between prompts pulled from the caller's own organization (trusted) and prompts pulled by owner/name from external accounts (untrusted). Attackers can exploit this by crafting prompt manifests containing serialized LangChain Runnable or PromptTemplate objects with malicious constructor kwargs. When deserialized, these objects may configure an LLM client with an attacker-controlled base_url or proxy, redirecting traffic and potentially disclosing provider credentials, system prompts, and retrieved context. Additionally, if include_model=True is passed, the deserialization allowlist expands to partner integration classes, further increasing attack surface. The fix requires callers to explicitly pass dangerously_pull_public_prompt=True (Python) or dangerouslyPullPublicPrompt: true (JS/TS) to acknowledge the trust boundary.
Affected products
- LangChain AI LangSmith SDK Python < 0.8.0, JS/TS < 0.6.0
- LangChain AI langsmith < 0.8.0 (pip), < 0.6.0 (npm)
- LangChain AI langchain < 0.3.30
- LangChain AI langchain-classic < 1.0.7
Timeline
- 2026-05-13: disclosed: GHSA-3644-q5cj-c5c7 published
- 2026-05-13: patched: LangSmith SDK Python >= 0.8.0 and JS/TS >= 0.6.0 released with dangerously_pull_public_prompt flag