<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:43:39 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290899</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290899</link>
      <description>EUVD-2026-290899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290899</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40190</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40190</link>
      <description>&lt;p&gt;LangSmith Client SDKs provide SDK&amp;#39;s for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecting all objects in the Node.js process. This vulnerability is fixed in 0.5.18.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LangSmith Client SDKs provide SDK&amp;#39;s for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() utility. The baseAssignValue() function only guards against the __proto__ key, but fails to prevent traversal via constructor.prototype. This allows an attacker who controls keys in data processed by the createAnonymizer() API to pollute Object.prototype, affecting all objects in the Node.js process. This vulnerability is fixed in 0.5.18.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40190</guid>
    </item>
    <item>
      <title>GHSA-fw9q-39r9-c252 — LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fw9q-39r9-c252</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: langsmith&lt;/p&gt;
&lt;p&gt;# GHSA-fw9q-39r9-c252: Prototype Pollution via Incomplete Lodash `set()` Guard in `langsmith-sdk`&lt;/p&gt;
&lt;p&gt;**Severity:** Medium (CVSS ~5.6)
**Status:** Fixed in 0.5.18&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The LangSmith JavaScript/TypeScript SDK (`langsmith`) contains an incomplete prototype pollution fix in its internally vendored lodash `set()` utility. The `baseAssignValue()` function only guards against the `__proto__` key, but fails to prevent traversal via `constructor.prototype`. This allows an attacker who controls keys in data processed by the `createAnonymizer()` API to pollute `Object.prototype`, affecting all objects in the Node.js process.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Products&lt;/p&gt;
&lt;p&gt;| Product | Affected Versions | Component |
|---------|-------------------|-----------|
| `langsmith` (npm) | &amp;lt;= 0.5.17 | `js/src/utils/lodash/baseAssignValue.ts`, `js/src/anonymizer/index.ts` |
| langchain-ai/langsmith-sdk | GitHub main branch (as of 2026-03-24) | JS/TypeScript SDK |&lt;/p&gt;
&lt;p&gt;**Not affected:** The Python SDK (`langsmith` on PyPI) does not use lodash or an equivalent pattern.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The SDK vendors an internal copy of lodash&amp;#39;s `set()` function at `js/src/utils/lodash/`. The `baseAssignValue()` function at `baseAssignValue.ts:11` implements a guard for prototype pollution:&lt;/p&gt;
&lt;p&gt;```typescript
function baseAssignValue(object: Record&amp;lt;string, any&amp;gt;, key: string, value: any) {
  if (key === &amp;#34;__proto__&amp;#34;) {
    Object.defineProperty(object, key, {
      configurable: true, enumerable: true, value: value, writable: tr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: langsmith&lt;/p&gt;
&lt;p&gt;# GHSA-fw9q-39r9-c252: Prototype Pollution via Incomplete Lodash `set()` Guard in `langsmith-sdk`&lt;/p&gt;
&lt;p&gt;**Severity:** Medium (CVSS ~5.6)
**Status:** Fixed in 0.5.18&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The LangSmith JavaScript/TypeScript SDK (`langsmith`) contains an incomplete prototype pollution fix in its internally vendored lodash `set()` utility. The `baseAssignValue()` function only guards against the `__proto__` key, but fails to prevent traversal via `constructor.prototype`. This allows an attacker who controls keys in data processed by the `createAnonymizer()` API to pollute `Object.prototype`, affecting all objects in the Node.js process.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Products&lt;/p&gt;
&lt;p&gt;| Product | Affected Versions | Component |
|---------|-------------------|-----------|
| `langsmith` (npm) | &amp;lt;= 0.5.17 | `js/src/utils/lodash/baseAssignValue.ts`, `js/src/anonymizer/index.ts` |
| langchain-ai/langsmith-sdk | GitHub main branch (as of 2026-03-24) | JS/TypeScript SDK |&lt;/p&gt;
&lt;p&gt;**Not affected:** The Python SDK (`langsmith` on PyPI) does not use lodash or an equivalent pattern.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The SDK vendors an internal copy of lodash&amp;#39;s `set()` function at `js/src/utils/lodash/`. The `baseAssignValue()` function at `baseAssignValue.ts:11` implements a guard for prototype pollution:&lt;/p&gt;
&lt;p&gt;```typescript
function baseAssignValue(object: Record&amp;lt;string, any&amp;gt;, key: string, value: any) {
  if (key === &amp;#34;__proto__&amp;#34;) {
    Object.defineProperty(object, key, {
      configurable: true, enumerable: true, value: value, writable: tr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fw9q-39r9-c252</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11284-1 — python313-langsmith-0.10.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11284-1</link>
      <description>&lt;p&gt;python313-langsmith-0.10.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-langsmith-0.10.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11284-1</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3046 — IBM Concert: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in IBM Concert ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3046</guid>
    </item>
  </channel>
</rss>
