CVE-2026-24055

Source
https://cve.org/CVERecord?id=CVE-2026-24055
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24055.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24055
Aliases
  • GHSA-pvq7-vvfj-p98x
Published
2026-01-22T03:07:03.784Z
Modified
2026-03-01T02:56:54.031236Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking
Details

Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId provided by the client without authentication or authorization. The projectId is preserved throughout the OAuth flow, and the callback stores installations based on this untrusted metadata. This allows an attacker to bind their Slack workspace to any project and potentially receive changes to prompts stored in Langfuse Prompt Management. An attacker can replace existing Prompt Slack Automation integrations or pre-register a malicious one, though the latter requires an authenticated user to unknowingly configure it despite visible workspace and channel indicators in the UI. This issue has been fixed in version 3.147.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24055.json"
}
References

Affected packages

Git / github.com/langfuse/langfuse

Affected ranges

Type
GIT
Repo
https://github.com/langfuse/langfuse
Events

Affected versions

v3.*
v3.100.0
v3.101.0
v3.102.0
v3.103.0
v3.104.0
v3.105.0
v3.106.0
v3.106.1
v3.106.2
v3.106.3
v3.106.4
v3.107.0
v3.108.0
v3.109.0
v3.110.0
v3.111.0
v3.112.0
v3.113.0
v3.114.0
v3.115.0
v3.116.0
v3.116.1
v3.117.0
v3.117.1
v3.117.2
v3.118.0
v3.119.0
v3.119.1
v3.120.0
v3.121.0
v3.122.0
v3.122.1
v3.122.2
v3.123.0
v3.123.1
v3.124.0
v3.124.1
v3.125.0
v3.126.0
v3.126.1
v3.127.0
v3.128.0
v3.129.0
v3.130.0
v3.131.0
v3.132.0
v3.133.0
v3.134.0
v3.135.0
v3.135.1
v3.136.0
v3.137.0
v3.138.0
v3.139.0
v3.140.0
v3.141.0
v3.142.0
v3.143.0
v3.144.0
v3.145.0
v3.146.0
v3.89.0
v3.90.0
v3.91.0
v3.92.0
v3.92.1
v3.93.0
v3.94.0
v3.95.0
v3.95.1
v3.95.2
v3.96.0
v3.96.1
v3.96.2
v3.97.0
v3.97.1
v3.97.2
v3.97.3
v3.97.4
v3.97.5
v3.98.0
v3.98.1
v3.98.2
v3.99.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24055.json"