I don't believe the samourai devs would be stupid enough to write their wallet to upload xpubs to their servers. Most wallets just upload single addresses, and have a hard-coded lookahead for derived addresses (e.g 50) on which they detect activity.
So while your whole xpub is not at risk here, your next 25/50/100 derived receive/change addresses could be, and practically speaking that is pretty sketch. If you launched Samourai recently, I would just sweep money and ditch the whole seed, then clean any coins you had on samourai.