Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40190

34
FAUCET Score

CVE-2026-40190 is a prototype pollution vulnerability in the LangSmith JavaScript/TypeScript SDK (langsmith) prior to version 0.5.18. The vulnerability exists in the internally vendored lodash set() utility function, where incomplete input validation allows attackers to bypass prototype pollution protections by traversing via constructor.prototype rather than the blocked __proto__ key. This flaw affects the createAnonymizer() API and can allow attackers who control input data to pollute Object.prototype, impacting all objects within the affected Node.js process. The vulnerability has a CVSS score of 5.6 (MEDIUM) with a network-based attack vector and high attack complexity. It requires no user interaction or special privileges and can result in limited impacts across confidentiality, integrity, and availability. The EPSS score of 0.00052 indicates this CVE ranks higher than only a small percentage of known vulnerabilities in terms of exploitation probability. There is currently no evidence of active exploitation in the wild, as this vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows inactive status on security tracking lists. No public exploit code appears to be readily available, and community attention remains minimal. Organizations using the LangSmith SDK should apply the patch to version 0.5.18 or later as a routine maintenance measure rather than an emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.5.18CPE matchmatch criteria
cpe:2.3:a:langchain:langsmith:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

5.6MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.2
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 3rd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: langsmithFixed in: 0.5.18
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-fw9q-39r9-c252medium

LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`

Apr 10, 2026

References

github.com / langchain-ai/langsmith-sdk/security/advisories/GHSA-fw9q-39r9-c252
ExploitVendor AdvisoryMitigation