MEDIUM Langfuse: Langfuse CVE-2026-41487 — member role can steal LLM provider keys
Why it matters
Your Langfuse version has an RBAC flaw: any project member can repoint an existing LLM connection at a server they control and capture the stored plaintext provider API key (OpenAI, Anthropic, …).
Fix it — 2 steps
- Upgrade Langfuse to 3.167.0 or later.
- Rotate stored LLM provider API keys for projects that had untrusted members.
Verify it’s fixed
curl -m 5 http://127.0.0.1:3000/api/public/health # version must be >= 3.167.0
References
- https://github.com/langfuse/langfuse/security/advisories/GHSA-2524-j966-gfgh
- https://nvd.nist.gov/vuln/detail/CVE-2026-41487
Not sure if your stack is exposed?
Run the free check — 30 seconds, safe read-only probes.
Scan your stack