CVE-2026-59152: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in langchain-ai langsmith-sdk
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a party with workspace trace-read access (for example a low-privilege workspace member, a contractor, or a compromised teammate account) gains the ability to read files from any server running TracingMiddleware, a capability outside that workspace's intended trust boundary. This vulnerability is fixed in 0.8.18.
AI Analysis
Technical Summary
CVE-2026-59152 is a path traversal vulnerability in the langchain-ai langsmith-sdk prior to version 0.8.18. The flaw allows an attacker who can send HTTP requests to a server running the TracingMiddleware component to read arbitrary files from the server's local filesystem. These files are then uploaded as trace attachments to the LangSmith platform. Exploitation may not require authentication depending on deployment. The vulnerability results in a trust boundary crossing, enabling parties with workspace trace-read access to access files beyond their authorized scope. The issue is resolved in version 0.8.18.
Potential Impact
An attacker with the ability to send HTTP requests to a vulnerable server can cause it to disclose arbitrary local files by uploading their contents as trace attachments. This allows users with read access to LangSmith workspace traces to access sensitive files on the server, violating intended trust boundaries. The impact is limited to confidentiality (partial information disclosure) and requires at least low privilege (workspace trace-read access). There is no impact on integrity or availability.
Mitigation Recommendations
Upgrade langsmith-sdk to version 0.8.18 or later, where this path traversal vulnerability is fixed. No other mitigations are indicated. Patch status is not explicitly stated as 'official-fix' but the description confirms the issue is fixed in 0.8.18. There is no indication that this is a cloud service; therefore, user-side patching is required.
CVE-2026-59152: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in langchain-ai langsmith-sdk
Description
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a server running the LangSmith SDK's TracingMiddleware can cause that server to read an arbitrary file from its local filesystem and upload the contents to LangSmith as a trace attachment. Depending on how the distributed trace system is deployed, triggering a read may not require authentication. Retrieving the contents requires read access to the LangSmith workspace the traces are sent to. The net effect is a trust-boundary crossing: a party with workspace trace-read access (for example a low-privilege workspace member, a contractor, or a compromised teammate account) gains the ability to read files from any server running TracingMiddleware, a capability outside that workspace's intended trust boundary. This vulnerability is fixed in 0.8.18.
CVSS v3.1
Score 5.0medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59152 is a path traversal vulnerability in the langchain-ai langsmith-sdk prior to version 0.8.18. The flaw allows an attacker who can send HTTP requests to a server running the TracingMiddleware component to read arbitrary files from the server's local filesystem. These files are then uploaded as trace attachments to the LangSmith platform. Exploitation may not require authentication depending on deployment. The vulnerability results in a trust boundary crossing, enabling parties with workspace trace-read access to access files beyond their authorized scope. The issue is resolved in version 0.8.18.
Potential Impact
An attacker with the ability to send HTTP requests to a vulnerable server can cause it to disclose arbitrary local files by uploading their contents as trace attachments. This allows users with read access to LangSmith workspace traces to access sensitive files on the server, violating intended trust boundaries. The impact is limited to confidentiality (partial information disclosure) and requires at least low privilege (workspace trace-read access). There is no impact on integrity or availability.
Mitigation Recommendations
Upgrade langsmith-sdk to version 0.8.18 or later, where this path traversal vulnerability is fixed. No other mitigations are indicated. Patch status is not explicitly stated as 'official-fix' but the description confirms the issue is fixed in 0.8.18. There is no indication that this is a cloud service; therefore, user-side patching is required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-02T16:50:27.886Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4bcbb327e9c79719c0cec2
Added to database: 07/06/2026, 15:37:23 UTC
Last enriched: 07/14/2026, 08:56:56 UTC
Last updated: 08/19/2026, 22:52:13 UTC
Views: 177
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.