Langfuse is a specialized observability and monitoring platform for large language model applications, maintaining a focused product footprint despite considerable prominence within its application domain. The vendor's disclosed vulnerabilities recur around access-control and authorization shortcomings—including improper authorization logic, cross-site request forgery, and exposure of sensitive data through query parameters—reflecting the sensitivity of LLM telemetry and the challenge of securing multi-tenant observability infrastructure. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Langfuse over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59305HIGH Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to da | Sep 24, 2025 | 7.6 | 28 | NO | NO |
CVE-2026-24055MEDIUM Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId | Jan 22, 2026 | 5.3 | 23 | NO | NO |
CVE-2025-65107MEDIUM Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations wi | Nov 21, 2025 | 6.5 | 22 | NO | NO |
CVE-2026-41487MEDIUM Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connectio | May 8, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-64504MEDIUM Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership APIs, the | Nov 10, 2025 | 5.0 | 20 | NO | NO |
CVE-2025-9799MEDIUM A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/r | Sep 1, 2025 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Langfuse.
Media articles that mention a CVE ID that affects a product developed by Langfuse — matched by CVE ID, not by vendor name.