Skip to content
Threat Feed
high advisory

CVE-2026-24055: Unauthenticated OAuth Slack Integration Leak in Langfuse

An improper access control vulnerability in Langfuse allows unauthenticated attackers to hijack Slack integrations and exfiltrate sensitive project prompt data via the /api/public/slack/install endpoint.

CVE search metadata

CVE search record: CVE-2026-24055. Severity: medium. CVSS: 5.3. EPSS: 0.44%. KEV: no. Product: Langfuse (3.89.0 - 3.146.0). Brief: CVE-2026-24055: Unauthenticated OAuth Slack Integration Leak in Langfuse. Brief link: https://feed.craftedsignal.io/briefs/2026-10-langfuse-slack-auth/

CVE-2026-24055 is an improper access control vulnerability (CWE-284, CWE-862) affecting Langfuse versions 3.89.0 through 3.146.0. The vulnerability resides in the /api/public/slack/install endpoint, which fails to enforce authentication or authorization checks during the Slack OAuth installation flow. By providing a target's unique projectId as a query parameter, an unauthenticated attacker can bind their own malicious Slack workspace to a victim's project. Once bound, any automation triggered within the victim's project that sends notifications to Slack will inadvertently exfiltrate sensitive data, including prompt content, metadata, labels, and tags, directly to the attacker-controlled Slack workspace. This vulnerability presents a high risk for organizations using Langfuse for prompt management, as it facilitates silent exfiltration of proprietary LLM development data.

Attack Chain

  1. Attacker identifies a target organization's unique Langfuse projectId through reconnaissance or information leakage.
  2. Attacker prepares a malicious Slack application configured with a callback URL pointing to the target Langfuse instance.
  3. Attacker crafts an HTTP GET request to the vulnerable endpoint: /api/public/slack/install?projectId=<victim-project-id>.
  4. The Langfuse application processes the request without authentication, triggering an OAuth redirect to Slack's authorization portal.
  5. Attacker authorizes the malicious Slack workspace within the OAuth flow, completing the binding process.
  6. The target victim, unaware of the unauthorized integration, performs routine operations such as updating or creating prompts.
  7. Langfuse automation triggers, sending sensitive prompt metadata and content to the attacker-controlled Slack workspace.
  8. Attacker gains full visibility into the victim's prompt library and development lifecycle events.

Impact

The successful exploitation of this vulnerability leads to the unauthorized exfiltration of sensitive AI development assets, including prompt templates, system instructions, and project metadata. Organizations utilizing Langfuse to manage LLM prompts are vulnerable to intellectual property theft. There is no requirement for user interaction or privilege acquisition to conduct this attack, making it highly impactful for publicly accessible or misconfigured Langfuse instances.

Recommendation

Prioritize the upgrade of all Langfuse deployments to version 3.147.0 or later to patch the authentication bypass on the Slack installation endpoint. Monitor web server logs for suspicious access to the /api/public/slack/install endpoint, particularly those originating from unauthenticated sessions or requests with unusual project identifiers. Review current Slack integrations within Langfuse settings to identify any unauthorized or unknown workspaces linked to sensitive projects.


Immediate actions

Upgrade Langfuse to 3.147.0

IT Operations 24h

Audit Slack integrations for unrecognized workspaces

SOC 24h

Threat Hunt

Search web logs for unauthenticated GET /api/public/slack/install

T1190 high high confidence hunt now

Data: Web application access logs

Mitigations

Upgrade Langfuse to version 3.147.0

immediate IT Operations

CVE-2026-24055

Detection coverage 1

Detect CVE-2026-24055 Exploitation Attempt

high

Detects unauthorized access attempts to the Slack installation API endpoint in Langfuse

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →