Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Langfuse

First CVE: Sep 1, 2025Active for: 1 yearTotal CVEs: 6

Langfuse is a specialized observability and monitoring platform for large language model applications, maintaining a focused product footprint despite considerable prominence within its application domain. The vendor's disclosed vulnerabilities recur around access-control and authorization shortcomings—including improper authorization logic, cross-site request forgery, and exposure of sensitive data through query parameters—reflecting the sensitivity of LLM telemetry and the challenge of securing multi-tenant observability infrastructure. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Langfuse over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 1, 2025
10 months ago
Most Recent CVE
May 8, 2026
77 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-59305HIGH
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to da
Sep 24, 20257.628NONO
CVE-2026-24055MEDIUM
Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId
Jan 22, 20265.323NONO
CVE-2025-65107MEDIUM
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations wi
Nov 21, 20256.522NONO
CVE-2026-41487MEDIUM
Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connectio
May 8, 20265.421NONO
CVE-2025-64504MEDIUM
Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership APIs, the
Nov 10, 20255.020NONO
CVE-2025-9799MEDIUM
A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/r
Sep 1, 20255.019NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
83%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low4 (66.7%)
High0 (0.0%)
None2 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Langfuse.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Langfuse — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Langfuse's Products

View all 3 CNAs →

Top CWEs