← advisory ledger

ADVISORY UNAUTH-2026-0037
TYPE cve
PRODUCT Langfuse
SEVERITY MEDIUM

MEDIUM

Langfuse CVE-2025-64504

published 2026-08-05 · updated 2026-08-05

Why it matters

Certain project membership APIs trusted a user-controlled orgId in authorization checks, letting any authenticated user enumerate names and email addresses of users in another organization on the same instance.

Affected versions

  • >=2.70.0,<2.95.11
  • >=3.0.0,<3.124.1

Fixed in: 2.95.11 / 3.124.1

Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29.

Fix it

Fix card: cve-2025-64504 →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0037 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0037. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.