Skip to content
Noroxi

langfuse records

6 published records for vendor langfuse.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
33.3%
Median publish → KEV
No record has entered KEV

All records

6 records
  • Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migratio

    HighCVSS 7.6No exploitEPSS 0%

    langfuse · langfuseSep 24, 2025

  • Langfuse SSO Account Takeover via CSRF or phishing attack

    MediumCVSS 6.5No exploitEPSS 0%

    langfuse · langfuseNov 21, 2025

  • Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking

    MediumCVSS 6.3Proof of conceptEPSS 0%

    langfuse · langfuseJan 22, 2026

  • Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys

    MediumCVSS 5.3No exploitEPSS 0%

    langfuse · langfuseMay 8, 2026

  • Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs

    MediumCVSS 5.0No exploitEPSS 0%

    langfuse · langfuseNov 10, 2025

  • Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery

    LowCVSS 1.3No exploitEPSS 0%

    langfuse · langfuseSep 1, 2025