CVE-2026-25528: LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection
The LangSmith SDK’s distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-25528 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →