CVE-2025-9799
Severity CVSS v4.0:
LOW
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
01/09/2025
Last modified:
02/12/2025
Description
A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
Impact
Base Score 4.0
2.30
Severity 4.0
LOW
Base Score 3.x
5.00
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:* | 3.88.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



