langsmith is vulnerable to Information Disclosure
59
Medium Risk
The Anthropic client wrapper records the arguments passed to Anthropic message calls as trace inputs and invocation metadata. When a caller supplies mcp_servers definitions, the wrapper copies them verbatim, including authorization tokens and other sensitive connection fields, into the data uploaded to LangSmith. This exposes MCP server credentials to anyone able to read the resulting traces. The fix redacts non-allowlisted mcp_servers fields with a placeholder and stops recording mcp_servers in Anthropic run invocation metadata.
You are affected if you are using a version that falls within the vulnerable range and you use the Anthropic wrapper with mcp_servers definitions that carry authorization tokens or other sensitive connection fields.
langsmith is vulnerable to Information Disclosure in versions 0.10.18 - 0.10.18.
Upgrade the langsmith library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant