{"id":"CVE-2026-41487","summary":"Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys","details":"Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is  a role-based-access control flaw in the LLM connection update flow. An authenticated, low-privileged user of role “member” in a project could request the update of an existing LLM connection to an attacker-controlled baseUrl, causing Langfuse to reuse the stored provider secret and redirect the test request to an attacker-controlled endpoint. This could expose the plaintext provider LLM API key for that connection. The attack is only possible if a user is already part of a project and has “member” scoped access. This issue has been patched in version 3.167.0.","aliases":["GHSA-2524-j966-gfgh"],"modified":"2026-08-12T03:51:46.961585095Z","published":"2026-05-08T14:27:48.588Z","related":["CGA-7jhc-9v5p-rwv9"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41487.json"},"references":[{"type":"WEB","url":"https://github.com/langfuse/langfuse/releases/tag/v3.167.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41487.json"},{"type":"ADVISORY","url":"https://github.com/langfuse/langfuse/security/advisories/GHSA-2524-j966-gfgh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41487"},{"type":"FIX","url":"https://github.com/langfuse/langfuse/commit/7527bb0d84bc0a3dc24a4b16d22ed2e46e6dddff"},{"type":"FIX","url":"https://github.com/langfuse/langfuse/commit/e12386f9d4368bbfff24a4ad7fd53641091605ff"},{"type":"FIX","url":"https://github.com/langfuse/langfuse/pull/13027"},{"type":"FIX","url":"https://github.com/langfuse/langfuse/pull/13055"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/langfuse/langfuse","events":[{"introduced":"aae1909466a4f676d77621a6349905d16b73873e"},{"fixed":"dd632fea9efe6cc9e125f3dcec051d4f3bab7669"},{"fixed":"7527bb0d84bc0a3dc24a4b16d22ed2e46e6dddff"},{"fixed":"e12386f9d4368bbfff24a4ad7fd53641091605ff"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.68.0"},{"fixed":"3.167.0"}]}}],"versions":["v3.166.0","v3.165.0","v3.164.0","v3.163.0","v3.162.0","v3.161.0","v3.160.0","v3.159.0","v3.158.0","v3.157.0","v3.156.0","v3.155.1","v3.155.0","v3.154.0","v3.154.1","v3.153.0","v3.152.0","v3.151.0","v3.150.0","v3.149.0","v3.148.0","v3.147.0","v3.146.0","v3.145.0","v3.144.0","v3.143.0","v3.142.0","v3.141.0","v3.140.0","v3.139.0","v3.138.0","v3.137.0","v3.136.0","v3.135.1","v3.135.0","v3.134.0","v3.133.0","v3.132.0","v3.131.0","v3.130.0","v3.129.0","v3.128.0","v3.127.0","v3.126.1","v3.126.0","v3.125.0","v3.124.1","v3.124.0","v3.123.1","v3.123.0","v3.122.2","v3.122.1","v3.122.0","v3.121.0","v3.120.0","v3.119.1","v3.119.0","v3.118.0","v3.117.2","v3.117.1","v3.117.0","v3.116.1","v3.116.0","v3.115.0","v3.114.0","v3.113.0","v3.112.0","v3.111.0","v3.110.0","v3.109.0","v3.108.0","v3.107.0","v3.106.4","v3.106.3","v3.106.2","v3.106.1","v3.106.0","v3.105.0","v3.104.0","v3.103.0","v3.102.0","v3.101.0","v3.100.0","v3.99.0","v3.98.2","v3.98.1","v3.98.0","v3.97.5","v3.97.4","v3.97.3","v3.97.2","v3.97.1","v3.97.0","v3.96.2","v3.96.1","v3.96.0","v3.95.2","v3.95.1","v3.95.0","v3.94.0","v3.93.0","v3.92.1","v3.92.0","v3.91.0","v3.90.0","v3.89.0","v3.88.1","v3.88.0","v3.87.1","v3.87.0","v3.86.1","v3.86.0","v3.85.2","v3.85.1","v3.85.0","v3.84.0","v3.83.0","v3.82.0","v3.81.1","v3.81.0","v3.80.1","v3.80.0","v3.79.1","v3.79.0","v3.78.2","v3.78.1","v3.78.0","v3.77.0","v3.76.0","v3.75.4","v3.75.3","v3.75.2","v3.75.1","v3.75.0","v3.74.0","v3.73.1","v3.73.0","v3.72.1","v3.72.0","v3.71.0","v3.70.0","v3.69.0","v3.68.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41487.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}