CVE-2026-40190
LangSmith SDK Prototype Pollution Vulnerability
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
The LangSmith Client SDK for Node.js has a vulnerability that allows an attacker controlling data keys to pollute `Object.prototype`, affecting all objects in the Node.js process. This could lead to unintended service behavior and impact application logic. Uncertainty exists regarding whether the `createAnonymizer()` A