CVE-2025-64504 affects Langfuse versions 2.70.0 through 2.95.10 and 3.0.0 through 3.124.0, allowing authenticated users to enumerate names and email addresses of users in other organizations due to improper authorization checks in certain project membership APIs. This medium severity vulnerability (CVSS 5.0) has a low attack complexity, requiring an authenticated user to know a target organization's ID, and only exposes user names and email addresses, not sensitive customer data. There is no evidence of active exploitation in Langfuse Cloud, and no public exploit code, Metasploit modules, or significant community discussion have been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.70.0, < 2.95.11CPE matchmatch criteria | cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.124.1CPE matchmatch criteria | cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.