CNNVD-202601-3891 Information
CNNVD ID
CNNVD-202601-3891
Related CVE
- CNNVD Published: 2026-01-22
Description (Chinese)
langfuse是Langfuse开源的一个大语言模型工程平台。 langfuse 3.146.0及之前版本存在访问控制错误漏洞,该漏洞源于/api/public/slack/install端点使用未经身份验证或授权的客户端提供的projectId发起Slack OAuth,可能导致攻击者将其Slack工作区绑定到任意项目并接收提示更改。
Description (English)
langfuse is a large-language modelling platform for the Langfuse open source. langfuse 3.146.0 and previous versions have access control error holes which originate from/api/public/slack/install endpoints that launch Slack OAuth using the project Id provided by an unidentified or unauthorized client, which could lead the attackers to bind their Slack workspace to an arbitrary item and to receive a prompt change.
Hazard Level
High
Vulnerability Type
访问控制错误
Affected Vendor
Langfuse
Published
2026-01-22
Last Modified
2026-02-24
References
https://github.com/langfuse/langfuse/commit/3adc89e4d72729eabef55e46888b8ce80a7e3b0a https://github.com/langfuse/langfuse/releases/tag/v3.147.0 https://github.com/langfuse/langfuse/security/advisories/GHSA-pvq7-vvfj-p98x https://langfuse.com/docs/prompt-management/features/webhooks-slack-integrations
Patch
https://github.com/langfuse/langfuse/releases
Share on: