CVE Explorer
CVE-2025-64504
Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership APIs, the server trusted a user‑controlled orgId and used it in authorization checks. As a result, any authenticated user on the same Langfuse instance could enumerate names and email addresses of users in another organization if they knew the target organization’s ID. Disclosure is limited to names and email addresses of member
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"langfuse","vendor":"langfuse","versions":[{"status":"affected","version":">= 2.70.0, < 2.95.11"},{"status":"affected","version":">= 3.0.0, < 3.124.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-202","description":"CWE-202: Exposure of Sensitive Information Through Data Queries","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/problemTypes/0/descriptions/0
Source references
6 source assertions{"name":"https://github.com/langfuse/langfuse/commit/67990ebfdcf0f0c32a6710efa7ddbda073812ab4","tags":["x_refsource_MISC"],"url":"https://github.com/langfuse/langfuse/commit/67990ebfdcf0f0c32a6710efa7ddbda073812ab4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/references/1
{"name":"https://github.com/langfuse/langfuse/commit/6c2529049a4c962928c435984c81a547a497e3e5","tags":["x_refsource_MISC"],"url":"https://github.com/langfuse/langfuse/commit/6c2529049a4c962928c435984c81a547a497e3e5"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/references/2
{"name":"https://github.com/langfuse/langfuse/releases/tag/v2.70.0","tags":["x_refsource_MISC"],"url":"https://github.com/langfuse/langfuse/releases/tag/v2.70.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/references/3
{"name":"https://github.com/langfuse/langfuse/releases/tag/v2.95.11","tags":["x_refsource_MISC"],"url":"https://github.com/langfuse/langfuse/releases/tag/v2.95.11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/references/4
{"name":"https://github.com/langfuse/langfuse/releases/tag/v3.124.1","tags":["x_refsource_MISC"],"url":"https://github.com/langfuse/langfuse/releases/tag/v3.124.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/references/5
{"name":"https://github.com/langfuse/langfuse/security/advisories/GHSA-94hf-6gqq-pj69","tags":["x_refsource_CONFIRM"],"url":"https://github.com/langfuse/langfuse/security/advisories/GHSA-94hf-6gqq-pj69"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ab59a014557e4751ef97a82a07ac2ea958db6318fd6d719552b37544f2decca8 · sha256:4649d2abbb9542e2… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.