SIGN IN SIGN UP

fix(deps): patch 6 security alerts across 4 packages (1 critical, 5 medium) (#478)

## Security Alert Patch

Resolves 6 open Dependabot security alerts (**1 critical, 5 medium**).

### Packages Updated

| Package | Old → New | Strategy | Scope | CVEs Resolved |
|---------|-----------|----------|-------|---------------|
| `protobufjs` | 7.5.4 → 7.5.5 | C (pnpm override) — parent ranges
already accept 7.5.5 | transitive (via modal, @grpc/proto-loader,
@opentelemetry/otlp-transformer) | **CVE-2026-41242** (critical) |
| `axios` | 1.13.6 → 1.15.1 | C (pnpm override) — @daytonaio/sdk
`^1.13.5` already accepts 1.15.x | transitive (via @daytonaio/sdk,
@daytonaio/api-client, @daytonaio/toolbox-api-client) | CVE-2025-62718,
CVE-2026-40175 |
| `follow-redirects` | 1.15.11 → 1.16.0 | C (pnpm override) — axios
`^1.15.11` already accepts 1.16.0 | transitive (via axios) |
GHSA-r4q5-vmmm-2653 |
| `langsmith` | floor raised to 0.5.19 | A (direct bump) —
`libs/deepagents` peerDep, `internal/eval-harness` dep | direct,
published | CVE-2026-40190, GHSA-rr7j-v2q5-chgv |

### Why pnpm.overrides for transitives

The three transitive bumps (protobufjs, axios, follow-redirects) use
pnpm.overrides because the parent packages' version ranges **already
allow the patched versions** — this is a lockfile refresh, not a
published-constraint change. End users installing `@langchain/daytona`
or `@langchain/modal` resolve their own lockfile and naturally get the
patched transitive versions; the overrides here just bring our lockfile
up to date.

For `langsmith`, the vulnerable 0.5.15 was pinned in
`libs/deepagents/peerDependencies` with floor `>=0.5.15`. Raising to
`>=0.5.19` closes the window for downstream consumers with stale
lockfiles.

### CVE Details

| ID | Package | Severity | Summary |
|----|---------|----------|---------|
| CVE-2026-41242 / GHSA-xq3m-2v4x-88gg | protobufjs | critical |
Arbitrary code execution in protobufjs |
| CVE-2025-62718 / GHSA-3p68-rc4w-qgx5 | axios | medium | NO_PROXY
hostname normalization bypass leading to SSRF |
| CVE-2026-40175 / GHSA-fvcv-3m26-pcqx | axios | medium | Unrestricted
cloud metadata exfiltration via header injection chain |
| GHSA-r4q5-vmmm-2653 | follow-redirects | medium | Leaks custom
authentication headers to cross-domain redirect targets |
| CVE-2026-40190 / GHSA-fw9q-39r9-c252 | langsmith | medium | Prototype
pollution via incomplete `__proto__` guard in internal lodash `set()` |
| GHSA-rr7j-v2q5-chgv | langsmith | medium | Streaming token events
bypass output redaction |

### Linear Tickets

No matching Linear tickets found (CLI unauthenticated in this
environment).

### Verification

- [x] `pnpm install --lockfile-only` clean — new lockfile contains
axios@1.15.1, protobufjs@7.5.5, follow-redirects@1.16.0,
langsmith@0.5.20 & 0.5.21 (vulnerable 0.5.15 fully removed)
- [x] `pnpm format:check` passes (313 files)
- [x] `pnpm lint` (oxlint) passes (0 warnings, 0 errors)
- [x] `pnpm test:unit` — 829/830 unit tests pass; the 1 failure and 6
unhandled errors are **pre-existing** on `main` (tied to recent
`ls_agent_type` feature #470 and broken
`@langchain/sandbox-standard-tests` module resolution), unrelated to
this patch
- [x] `pnpm typecheck` failure in `libs/standard-tests` is pre-existing
on `main`, unrelated to this patch
- [x] No major-version bumps; minimum-safe versions used throughout

🤖 Submitted by langster-patch
J
John Kennedy committed
6eb421ff9e8ce5b0207c773a64da1dea05916d72
Parent: 4c0c219
Committed by GitHub <noreply@github.com> on 4/21/2026, 9:39:29 PM