AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Injected Tool Arg Declared With Pydantic Alias Is Not Filtered From On_tool_start'S Inputs And Input_str

An injected tool argument declared with a Pydantic alias (e.g., Field(alias="private_token")) is not stripped from the inputs and input_str passed to on_tool_start callbacks, leaking internal sentinel values to tracing backends.

highConfidence 95%LangchainAffected V1.6.5

Origin Analysis

BaseTool._filter_injected_args in langchain_core/tools/base.py collects only canonical field names, function argument names, and FILTERED_ARGS. It does not collect Pydantic aliases, validation_aliases, or names inside AliasChoices/AliasPath. As a result, when the input dict uses the alias key, the filter misses it and the injected value remains in the dict used for callbacks.
1. Define a Pydantic model Args with x: int and secret: Annotated[str, InjectedToolArg] = Field(alias="private_token"). 2. Build a StructuredTool.from_function with args_schema=Args. 3. Invoke the tool with tool.invoke({"x": 1, "private_token": "INTERNAL_SENTINEL"}, {"callbacks": [Capture()]}). 4. Observe that Capture.on_tool_start receives inputs containing {'x': 1, 'private_token': 'INTERNAL_SENTINEL'} instead of only {'x': 1}.

Fixing Code Block

Edge Case Audit

This change will strip alias keys from callback inputs, which is the intended security fix but may break users who previously relied on seeing those keys in tracing. The deepcopy for nested AliasPath deletion can introduce performance overhead and may fail on objects that are not deepcopy-able; consider a targeted deletion helper if performance is critical. Caching _injected_args per instance assumes the schema is immutable; dynamic schema changes while the tool is in use will not be picked up until cache is reset. Concurrent first-time invocation of the same tool instance may race on _injected_args_collected initialization; existing code likely has the same race, but the new code adds no extra safety. Rollback: pin langchain-core to a version before this change or revert the modified function and helper code. Test with pydantic <2.5 and nested models before deploying widely.

Ecosystem Topology