CVE-2026-24055
MED 5.3Langfuse is an open source large language model engineering platform. In versions 3.146.0 and below, the /api/public/slack/install endpoint initiates Slack OAuth using a projectId provided by the client without authentication or authorization. The projectId is preserved throughout the OAuth flow, and the callback stores installations based on this untrusted metadata. This allows an attacker to bind their Slack workspace to any project and potentially receive changes to prompts stored in Langfuse Prompt Management. An attacker can replace existing Prompt Slack Automation integrations or pre-register a malicious one, though the latter requires an authenticated user to unknowingly configure it despite visible workspace and channel indicators in the UI. This issue has been fixed in version 3.147.0.
Affected Applications in Environment
12
fuse
v2.9.9-17.el9
27 devices
fuse
v2.9.2-4ubuntu4.14.04.1
1 device
fuse
v2.9.7-19.el8
3 devices
fuse
v2.9.7-1ubuntu1
1 device
fuse
v2.9.4-1ubuntu3.1
3 devices
fuse
v2.9.4-1ubuntu3.1+esm1
1 device
fuse
v2.9.9-17.el9
2 devices
fuse
v2.9.7-19.0.1.el8
6 devices
fuse
v2.9.9-17.el9
1 device
fuse
v2.9.7-16.el8
2 devices
fuse
v2.9.2-11.el7
1 device
fuse
v2.9.9-17.el9
1 device
Affected Devices
49
atc.db.usu.edu
Linux
chela03
Linux
chela04
Linux
chela05
Linux
cleanaddressdev.banner.usu.edu
Linux
devjobsub.banner.usu.edu
Linux
dpapsb-161390.aggies.usu.edu
Linux
dpapsb-191594.mypc.usu.edu
Linux
el103-02.ece.usu.edu
Linux
el103-03.ece.usu.edu
Linux
el103-04.ece.usu.edu
Linux
el103-05.ece.usu.edu
Linux
el103-07.ece.usu.edu
Linux
el103-08.ece.usu.edu
Linux
el103-09.ece.usu.edu
Linux
el103-10.ece.usu.edu
Linux
el103-14.ece.usu.edu
Linux
el103-15.ece.usu.edu
Linux
el103-16.ece.usu.edu
Linux
el103-17.ece.usu.edu
Linux
el103-18.ece.usu.edu
Linux
el103-19.ece.usu.edu
Linux
el103-20.ece.usu.edu
Linux
el120-01.ece.usu.edu
Linux
el120-02.ece.usu.edu
Linux
el120-03.ece.usu.edu
Linux
el120-04.ece.usu.edu
Linux
el120-05.ece.usu.edu
Linux
el120-06.ece.usu.edu
Linux
el120-08.ece.usu.edu
Linux
el120-09.ece.usu.edu
Linux
el120-10.ece.usu.edu
Linux
el120-11.ece.usu.edu
Linux
el120-12.ece.usu.edu
Linux
el120-14.ece.usu.edu
Linux
eprocdev.banner.usu.edu
Linux
facreadyprod.pplant.usu.edu
Linux
facreadytestrhel.pplant.usu.edu
Linux
facshibsp2.pplant.usu.edu
Linux
guru.cluster
Linux
hotcheeto
Linux
my2
Linux
oms.db.usu.edu
Linux
paymentworksdev.banner.usu.edu
Linux
web04a
Linux
web05
Linux
web21
Linux
web22
Linux
zldtst.db.usu.edu
Linux
References
4
- https://github.com/langfuse/langfuse/commit/3adc89e4d72729eabef55e46888b8ce80a7e3b0a
- https://github.com/langfuse/langfuse/releases/tag/v3.147.0
- https://github.com/langfuse/langfuse/security/advisories/GHSA-pvq7-vvfj-p98x
- https://langfuse.com/docs/prompt-management/features/webhooks-slack-integrations