Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-41487
Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys
CVE-2026-24055
Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking
CVE-2025-65107
Langfuse SSO Account Takeover via CSRF or phishing attack
CVE-2025-64504
Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs
CVE-2025-59305
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
