Authorization Flaw in Langfuse Affects User Data Exposure
CVE-2025-64504
What is CVE-2025-64504?
Langfuse, an open-source platform for managing large language models, contains a significant vulnerability in its project membership APIs. Authenticated users can exploit this flaw to access the names and email addresses of users from other organizations within the same Langfuse instance by manipulating the organization ID in API requests. Although customer data remains safeguarded, the flaw poses risks of unwanted user data exposure. Affected versions require an upgrade to recent patches (v2.95.11 and v3.124.1) to mitigate this risk effectively. The Langfuse Cloud environment has been reviewed with no confirmed incidents of exploitation, particularly where enterprise Single Sign-On (SSO) setups limit the attack vector.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
langfuse >= 2.70.0, < 2.95.11 < 2.70.0, 2.95.11
langfuse >= 3.0.0, < 3.124.1 < 3.0.0, 3.124.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
