Critical LangSmith Account Takeover Vulnerability Puts Users at Risk
ID: 63393554-a49f-5c1c-bbeb-1908388d9118
STIX ID: report--63393554-a49f-5c1c-bbeb-1908388d9118
Feed Name: cybersecurityNews.com
Miggo Security disclosed a critical LangSmith vulnerability (CVE-2026-25750) in the Studio front-end: an attacker-controlled baseUrl could be used to route an authenticated user's API requests and session tokens to a malicious domain, allowing silent account takeover and potential access to raw AI traces, system prompts, and sensitive data. LangChain mitigated the issue by implementing a strict allowed-origins policy; cloud customers were remediated by December 15, 2025, and self-hosted administrators must upgrade to LangSmith 0.12.71 or Helm chart langsmith-0.12.33+ to be protected. The advisory states there is no evidence of active exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
