CVE-2026-40190 is a prototype pollution vulnerability in the LangSmith JavaScript/TypeScript SDK (langsmith) prior to version 0.5.18. The vulnerability exists in the internally vendored lodash set() utility function, where incomplete input validation allows attackers to bypass prototype pollution protections by traversing via constructor.prototype rather than the blocked __proto__ key. This flaw affects the createAnonymizer() API and can allow attackers who control input data to pollute Object.prototype, impacting all objects within the affected Node.js process. The vulnerability has a CVSS score of 5.6 (MEDIUM) with a network-based attack vector and high attack complexity. It requires no user interaction or special privileges and can result in limited impacts across confidentiality, integrity, and availability. The EPSS score of 0.00052 indicates this CVE ranks higher than only a small percentage of known vulnerabilities in terms of exploitation probability. There is currently no evidence of active exploitation in the wild, as this vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows inactive status on security tracking lists. No public exploit code appears to be readily available, and community attention remains minimal. Organizations using the LangSmith SDK should apply the patch to version 0.5.18 or later as a routine maintenance measure rather than an emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.18CPE matchmatch criteria | cpe:2.3:a:langchain:langsmith:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.