CVE-2026-25750 describes a URL parameter injection vulnerability in LangSmith Studio, affecting both LangSmith Cloud and self-hosted deployments of Langchain applications using Helm charts prior to version 0.12.71. This flaw allows unauthorized access to user accounts through stolen authentication tokens. The vulnerability carries a high CVSS score of 8.5, indicating a significant risk. It requires user interaction (social engineering) to trick authenticated users into clicking a specially crafted malicious link, which then transmits their bearer token, user ID, and workspace ID to an attacker-controlled server. While stolen tokens expire after 5 minutes, an attacker could impersonate the victim and access their LangSmith resources. There is currently no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.12.71CPE matchmatch criteria | cpe:2.3:a:langchain:langsmith:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.