AE Agent Errors
AE-GNRV7889

Pulling a public Hub prompt deserializes attacker-controlled manifests, allowing model base_url redirection and secret disclosure

SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM

LangSmith SDK prompt pull methods fetched and deserialized prompt manifests from public owner/name identifiers without distinguishing them from the caller's own organization. A malicious manifest could instantiate LangChain objects with attacker-supplied constructor arguments, e.g. an LLM client with an attacker-controlled base_url, redirecting LLM traffic including prompts and credentials, or embed attacker-controlled system messages.

Framework / agent
LangSmith SDK · LLM applications/agents loading prompts from LangSmith Hub
Remediation attempts
APPLIED
Recurrence
not documented
Source languages
en
Updated
2026-09-29

Sources

Symptoms

  • The SDK instantiates LangChain objects from a pulled public prompt with attacker-supplied constructor arguments instead of treating the manifest as inert data
  • LLM traffic can be redirected to an attacker-controlled endpoint, disclosing prompts, retrieved context and provider credentials
  • Secret references can read environment variables at deserialization time when secrets_from_env is enabled
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-GNRV7889. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.