langfuse records
6 published records for vendor langfuse.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control2
- CWE-285 Improper Authorization2
- CWE-202 Exposure of Sensitive Information Through Data Queries1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2025-59305No exploit | Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migratiolangfuse · langfuse · CWE-285 | High7.6 | — | 0.3% | Sep 24, 2025 |
26Monitor | CVE-2025-65107No exploit | Langfuse SSO Account Takeover via CSRF or phishing attacklangfuse · langfuse · CWE-285 | Medium6.5 | — | 0.2% | Nov 21, 2025 |
25Monitor | CVE-2026-24055Proof of concept | Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linkinglangfuse · langfuse · CWE-284 | Medium6.3 | — | 0.4% | Jan 22, 2026 |
21Monitor | CVE-2026-41487No exploit | Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keyslangfuse · langfuse · CWE-284 | Medium5.3 | — | 0.3% | May 8, 2026 |
20Monitor | CVE-2025-64504No exploit | Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIslangfuse · langfuse · CWE-202 | Medium5.0 | — | 0.3% | Nov 10, 2025 |
5Monitor | CVE-2025-9799No exploit | Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgerylangfuse · langfuse · CWE-918 | Low1.3 | — | 0.3% | Sep 1, 2025 |
- CVE-2025-5930530Monitor
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migratio
HighCVSS 7.6No exploitEPSS 0%langfuse · langfuseSep 24, 2025
- CVE-2025-6510726Monitor
Langfuse SSO Account Takeover via CSRF or phishing attack
MediumCVSS 6.5No exploitEPSS 0%langfuse · langfuseNov 21, 2025
- CVE-2026-2405525Monitor
Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking
MediumCVSS 6.3Proof of conceptEPSS 0%langfuse · langfuseJan 22, 2026
- CVE-2026-4148721Monitor
Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys
MediumCVSS 5.3No exploitEPSS 0%langfuse · langfuseMay 8, 2026
- CVE-2025-6450420Monitor
Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs
MediumCVSS 5.0No exploitEPSS 0%langfuse · langfuseNov 10, 2025
- CVE-2025-97995Monitor
Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
LowCVSS 1.3No exploitEPSS 0%langfuse · langfuseSep 1, 2025