Loading
Client library to connect to the LangSmith Observability and Evaluation Platform.
Declares an LLM dependency since 2025-03-14 (version 0.3.15).
Advisories that name langsmith as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| GHSA-f4xh-w4cj-qxq8: LangSmith SDK TracingMiddleware: Arbitrary server-side file read | High | < 0.8.18 | 0.8.18 | 2026-06-19 |
| CVE-2026-45134GHSA-3644-q5cj-c5c7: LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning | High | < 0.6.0 | 0.6.0 | 2026-05-13 |
| GHSA-rr7j-v2q5-chgv: LangSmith SDK: Streaming token events bypass output redaction | Medium | <= 0.7.30 | 0.7.31 | 2026-04-16 |
| CVE-2026-40190GHSA-fw9q-39r9-c252: LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()` | Medium | <= 0.5.17 | 0.5.18 | 2026-04-10 |
As declared in PyPI metadata for version 0.14.7. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.