<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Langfuse - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/langfuse/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 01:00:59 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/langfuse/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-24055: Unauthenticated OAuth Slack Integration Leak in Langfuse</title><link>https://feed.craftedsignal.io/briefs/2026-10-langfuse-slack-auth/</link><pubDate>Mon, 05 Oct 2026 01:00:59 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-langfuse-slack-auth/</guid><description>An improper access control vulnerability in Langfuse allows unauthenticated attackers to hijack Slack integrations and exfiltrate sensitive project prompt data via the /api/public/slack/install endpoint.</description><content:encoded><![CDATA[<p>CVE-2026-24055 is an improper access control vulnerability (CWE-284, CWE-862) affecting Langfuse versions 3.89.0 through 3.146.0. The vulnerability resides in the /api/public/slack/install endpoint, which fails to enforce authentication or authorization checks during the Slack OAuth installation flow. By providing a target's unique projectId as a query parameter, an unauthenticated attacker can bind their own malicious Slack workspace to a victim's project. Once bound, any automation triggered within the victim's project that sends notifications to Slack will inadvertently exfiltrate sensitive data, including prompt content, metadata, labels, and tags, directly to the attacker-controlled Slack workspace. This vulnerability presents a high risk for organizations using Langfuse for prompt management, as it facilitates silent exfiltration of proprietary LLM development data.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target organization's unique Langfuse projectId through reconnaissance or information leakage.</li>
<li>Attacker prepares a malicious Slack application configured with a callback URL pointing to the target Langfuse instance.</li>
<li>Attacker crafts an HTTP GET request to the vulnerable endpoint: /api/public/slack/install?projectId=&lt;victim-project-id&gt;.</li>
<li>The Langfuse application processes the request without authentication, triggering an OAuth redirect to Slack's authorization portal.</li>
<li>Attacker authorizes the malicious Slack workspace within the OAuth flow, completing the binding process.</li>
<li>The target victim, unaware of the unauthorized integration, performs routine operations such as updating or creating prompts.</li>
<li>Langfuse automation triggers, sending sensitive prompt metadata and content to the attacker-controlled Slack workspace.</li>
<li>Attacker gains full visibility into the victim's prompt library and development lifecycle events.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of this vulnerability leads to the unauthorized exfiltration of sensitive AI development assets, including prompt templates, system instructions, and project metadata. Organizations utilizing Langfuse to manage LLM prompts are vulnerable to intellectual property theft. There is no requirement for user interaction or privilege acquisition to conduct this attack, making it highly impactful for publicly accessible or misconfigured Langfuse instances.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of all Langfuse deployments to version 3.147.0 or later to patch the authentication bypass on the Slack installation endpoint. Monitor web server logs for suspicious access to the /api/public/slack/install endpoint, particularly those originating from unauthenticated sessions or requests with unusual project identifiers. Review current Slack integrations within Langfuse settings to identify any unauthorized or unknown workspaces linked to sensitive projects.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>langfuse</category><category>cve-2026-24055</category><category>access-control</category><category>slack-oauth</category><category>data-exfiltration</category></item></channel></rss>