<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:44:33.828279+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290899</id>
    <title>EUVD-2026-290899</title>
    <updated>2026-10-03T07:44:33.831832+00:00</updated>
    <content>EUVD-2026-290899</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290899"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40190</id>
    <title>fkie_cve-2026-40190</title>
    <updated>2026-10-03T07:44:33.831866+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecting all objects in the Node.js process. This vulnerability is fixed in 0.5.18.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fw9q-39r9-c252</id>
    <title>GHSA-fw9q-39r9-c252 — LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set…</title>
    <updated>2026-10-03T07:44:33.831900+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: langsmith</p>
<p># GHSA-fw9q-39r9-c252: Prototype Pollution via Incomplete Lodash `set()` Guard in `langsmith-sdk`</p>
<p>**Severity:** Medium (CVSS ~5.6)
**Status:** Fixed in 0.5.18</p>
<p>---</p>
<p>## Summary</p>
<p>The LangSmith JavaScript/TypeScript SDK (`langsmith`) contains an incomplete prototype pollution fix in its internally vendored lodash `set()` utility. The `baseAssignValue()` function only guards against the `__proto__` key, but fails to prevent traversal via `constructor.prototype`. This allows an attacker who controls keys in data processed by the `createAnonymizer()` API to pollute `Object.prototype`, affecting all objects in the Node.js process.</p>
<p>---</p>
<p>## Affected Products</p>
<p>| Product | Affected Versions | Component |
|---------|-------------------|-----------|
| `langsmith` (npm) | &lt;= 0.5.17 | `js/src/utils/lodash/baseAssignValue.ts`, `js/src/anonymizer/index.ts` |
| langchain-ai/langsmith-sdk | GitHub main branch (as of 2026-03-24) | JS/TypeScript SDK |</p>
<p>**Not affected:** The Python SDK (`langsmith` on PyPI) does not use lodash or an equivalent pattern.</p>
<p>---</p>
<p>## Root Cause</p>
<p>The SDK vendors an internal copy of lodash's `set()` function at `js/src/utils/lodash/`. The `baseAssignValue()` function at `baseAssignValue.ts:11` implements a guard for prototype pollution:</p>
<p>```typescript
function baseAssignValue(object: Record&lt;string, any&gt;, key: string, value: any) {
  if (key === "__proto__") {
    Object.defineProperty(object, key, {
      configurable: true, enumerable: true, value: value, writable: tr…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fw9q-39r9-c252"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11284-1</id>
    <title>openSUSE-SU-2026:11284-1 — python313-langsmith-0.10.3-1.1 on GA media</title>
    <updated>2026-10-03T07:44:33.831967+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python313-langsmith-0.10.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11284-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</id>
    <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
    <updated>2026-10-03T07:44:33.831987+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046"/>
  </entry>
</feed>
