| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-24055 | Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking | langfuse | langfuse | - | - | 2026-01-22 03:07:04 | Deep Dive |
| CVE-2025-65107 | Langfuse SSO Account Takeover via CSRF or phishing attack | langfuse | langfuse | Medium | 6.5 | 2025-11-21 21:49:19 | Deep Dive |
| CVE-2025-64504 | Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs | langfuse | langfuse | Medium | 5.0 | 2025-11-10 21:51:37 | Deep Dive |
| CVE-2025-9799 | Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery | - | Langfuse | Medium | 5.0 | 2025-09-01 22:02:09 | Deep Dive |