Langfuse
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
đź“… Data spans from September 1, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys
Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking
Langfuse SSO Account Takeover via CSRF or phishing attack
Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs
Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
Monitor Langfuse in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.