CVE-2026-24055 | Langfuse up to 3.146.x Slack install access control (GHSA-pvq7-vvfj-p98x)
A vulnerability classified as critical was found in Langfuse up to 3.146.x. The impacted element is an unknown function of the file /api/public/slack/install of the component Slack. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-24055. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.