CVE-2025-65107: Langfuse SSO Account Takeover via CSRF or phishing attack
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH<PROVIDER>CHECK setting, a potential account takeover may happen if an authenticated user is made to call a specifically crafted URL via a CSRF or phishing attack. This issue has been patched in versions 2.95.12 and 3.131.0. A workaround for this issue involves setting AUTH<PROVIDER>CHECK.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65107?
CVE-2025-65107 is classified as a high severity vulnerability due to the risk of account takeover.
How do I fix CVE-2025-65107?
To fix CVE-2025-65107, ensure that the AUTH_<PROVIDER>_CHECK setting is explicitly configured in your SSO provider settings.
Which versions of Langfuse are affected by CVE-2025-65107?
CVE-2025-65107 affects Langfuse versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0.
What kind of attack does CVE-2025-65107 enable?
CVE-2025-65107 potentially enables an account takeover attack under certain SSO configurations.
Is there any mitigation for CVE-2025-65107?
The best mitigation for CVE-2025-65107 is to update to a patched version of Langfuse or properly configure your SSO settings.