CVE-2025-9799: Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9799?
CVE-2025-9799 has been classified as a critical vulnerability due to the potential for server-side manipulation.
How do I fix CVE-2025-9799?
To fix CVE-2025-9799, update Langfuse Webhook Handler to version 3.89.0 or later.
What software is affected by CVE-2025-9799?
CVE-2025-9799 affects Langfuse Webhook Handler versions up to and including 3.88.0.
What type of vulnerability is CVE-2025-9799?
CVE-2025-9799 is a server-side manipulation vulnerability located in the promptChangeEventSourcing function.
When was CVE-2025-9799 disclosed?
CVE-2025-9799 was disclosed in 2025, highlighting a critical security risk in earlier versions of Langfuse.