Langfuse

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-41487

    Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys

    Last Modified: May 13, 2026
    Published: May 08, 2026

    CVE-2026-24055

    Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking

    Last Modified: Apr 18, 2026
    Published: Jan 22, 2026

    CVE-2025-65107

    Langfuse SSO Account Takeover via CSRF or phishing attack

    Last Modified: Dec 03, 2025
    Published: Nov 21, 2025

    CVE-2025-64504

    Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs

    Last Modified: Dec 02, 2025
    Published: Nov 10, 2025

    CVE-2025-59305

    Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.

    Last Modified: Dec 02, 2025
    Published: Sep 24, 2025
    Items Per Page
    Langfuse Vulnerabilities & Security CVEs | CVE-DB