AE-GNRV7889
Pulling a public Hub prompt deserializes attacker-controlled manifests, allowing model base_url redirection and secret disclosure
SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
LangSmith SDK prompt pull methods fetched and deserialized prompt manifests from public owner/name identifiers without distinguishing them from the caller's own organization. A malicious manifest could instantiate LangChain objects with attacker-supplied constructor arguments, e.g. an LLM client with an attacker-controlled base_url, redirecting LLM traffic including prompts and credentials, or embed attacker-controlled system messages.
- Framework / agent
- LangSmith SDK · LLM applications/agents loading prompts from LangSmith Hub
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning — https://github.com/langchain-ai/langsmith-sdk, retrieved 2026-09-29
Symptoms
- The SDK instantiates LangChain objects from a pulled public prompt with attacker-supplied constructor arguments instead of treating the manifest as inert data
- LLM traffic can be redirected to an attacker-controlled endpoint, disclosing prompts, retrieved context and provider credentials
- Secret references can read environment variables at deserialization time when secrets_from_env is enabled
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-GNRV7889. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.