CVE-2026-41182: LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redac...

Added to the CISA Known Exploited Vulnerabilities catalog on 23 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.3.

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of the Python SDK, the LangSmith SDK's output redaction controls (hideOutputs in JS, hide_outputs in Python) do not apply to streaming token events. Wh...

Required action: Review and patch if applicable to your AI infrastructure.