LangChain SSRF redirect bypass and LangSmith Studio token-leak vulnerabilities
Two LangChain vulnerabilities were disclosed and patched: a redirect-based SSRF bypass in RecursiveUrlLoader in @langchain/community (CVE-2026-27795), which allowed a validated public URL to redirect to internal or metadata endpoints, and a URL parameter injection flaw in LangSmith Studio (CVE-2026-25750) that leaked bearer tokens, user IDs and workspace IDs to attacker-controlled servers when users clicked crafted links.
Disclosed 25 February 2026 · Record updated 13 September 2026
Impact
SSRF bypass could let a request reach internal or cloud metadata endpoints; the LangSmith Studio flaw could let an attacker steal a short-lived bearer token and impersonate an authenticated user across LangSmith Cloud and self-hosted workspaces.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-27795
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-25750
