Vulnerability  ·  2026-04-18

LangChain LangSmith Studio URL Parameter Injection Vulnerability

VulnerabilityMedium impactCVE-2026-25750
A URL parameter injection vulnerability in LangSmith Studio allows unauthorized access to user accounts through stolen authentication tokens. Affects versions prior to langchain-ai/helm version 0.12.71.
Malicious links can extract bearer tokens, user IDs, and workspace IDs from authenticated LangSmith users, transmitting credentials to attacker-controlled servers.
LangChain LangSmith Studio installations prior to version 0.12.71.
Update to langchain-ai/helm version 0.12.71 or later. Review user authentication logs for suspicious access patterns.
Sources
NVD
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →