CVE-2026-40190 - LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
CVE ID :CVE-2026-40190
Published : April 10, 2026, 8:16 p.m. | 3 hours, 52 minutes ago
Description :LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to ...
Related Vulnerabilities
- CVE-2026-5460: A heap use-after-free exists in wolfSSL's TLS 1.3 post-quantum cryptography (PQC) hybrid KeyShare pr MEDIUM
- CVE-2026-31941: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, Chamilo LMS contains a HIGH
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
- CVE-2026-35621: OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command HIGH
- CVE-2026-40089: Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audi MEDIUM
Related Coverage
Threat Actors