CVE-2025-9799 Overview
CVE-2025-9799 is a Server-Side Request Forgery (SSRF) vulnerability [CWE-918] affecting Langfuse versions up to 3.88.0. The flaw resides in the promptChangeEventSourcing function in web/src/features/prompts/server/routers/promptRouter.ts, part of the Webhook Handler component. An authenticated attacker can manipulate webhook processing to coerce the Langfuse server into issuing arbitrary HTTP requests to attacker-controlled or internal destinations. Exploitation requires high attack complexity and low privileges, and a public exploit disclosure exists through VulDB. The vendor is Langfuse, an open-source LLM engineering platform widely deployed in AI application development pipelines.
Critical Impact
Successful exploitation enables an attacker to pivot through the Langfuse server to reach internal services, cloud metadata endpoints, or other network resources normally unreachable from the public internet.
Affected Products
- Langfuse langfuse versions up to and including 3.88.0
- Deployments using the Webhook Handler feature in prompt change event sourcing
- Self-hosted and container-based Langfuse installations exposing the webhook route
Discovery Timeline
- 2025-09-01 - CVE-2025-9799 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9799
Vulnerability Analysis
The vulnerability sits inside the promptChangeEventSourcing function used by Langfuse to dispatch webhook notifications when prompt resources change. The handler accepts URL input that is passed to a server-side HTTP client without sufficient validation of the destination host, scheme, or address range. An attacker with low privileges on the Langfuse instance can submit crafted webhook configuration or prompt events that trigger outbound requests to arbitrary targets.
Because the request originates from the Langfuse backend, it inherits the server's network position. This permits reconnaissance and interaction with hosts behind the perimeter, including cloud instance metadata services, internal admin APIs, and lateral service endpoints. The impact is bounded by the low confidentiality, integrity, and availability sub-scores assigned by the vendor, but SSRF against AI infrastructure often chains with credential theft from metadata endpoints.
Root Cause
The root cause is missing or insufficient validation of user-controllable URLs before they are passed to the outbound HTTP client inside promptChangeEventSourcing. The code path does not enforce an allowlist of destinations, filter private IP address ranges, or restrict permitted URL schemes.
Attack Vector
The attack is remote and network-based. An authenticated user with sufficient permissions to configure prompt webhooks submits a destination URL pointing to internal infrastructure. When the prompt change event fires, the Langfuse server issues an HTTP request to the attacker-chosen address and may return response data or side-channel timing information to the attacker.
No verified exploit code is published in a public repository, though VulDB entry 322114 documents the technique. See the GitHub issue #8522 for the maintainer discussion.
Detection Methods for CVE-2025-9799
Indicators of Compromise
- Outbound HTTP requests from the Langfuse server process to RFC1918 ranges, link-local 169.254.169.254, or loopback addresses
- Webhook configurations stored in the Langfuse database whose target URL resolves to internal infrastructure
- Unexpected access entries in internal service logs sourced from the Langfuse application IP
Detection Strategies
- Audit the Langfuse database for webhook destinations that resolve to private, link-local, or metadata addresses
- Inspect application logs for calls into promptChangeEventSourcing paired with non-standard destination hosts
- Correlate egress proxy or firewall logs against the Langfuse workload identity for anomalous destination patterns
Monitoring Recommendations
- Route all Langfuse egress through a filtering proxy and alert on requests to cloud metadata endpoints
- Enable DNS query logging on the Langfuse workload and alert on resolutions to internal zones
- Track authentication events that create or modify webhook configurations and flag bursts from a single account
How to Mitigate CVE-2025-9799
Immediate Actions Required
- Upgrade Langfuse to a release later than 3.88.0 that remediates the promptChangeEventSourcing SSRF
- Restrict network egress from the Langfuse workload to an explicit allowlist of required destinations
- Disable or lock down webhook creation permissions until the patched version is deployed
- Rotate any cloud instance credentials that may have been exposed to the Langfuse host via metadata services
Patch Information
Refer to the upstream maintainer response in Langfuse GitHub Issue #8522 and the VulDB advisory #322114 for the fix commit and recommended target version. Apply the vendor-released update before re-enabling webhook functionality.
Workarounds
- Place the Langfuse backend behind an egress proxy that denies requests to private, loopback, and link-local address ranges
- Enforce IMDSv2 on AWS workloads to require session tokens for metadata access, blocking blind SSRF retrieval
- Remove or restrict the webhook feature at the reverse proxy layer if upgrade is not immediately feasible
# Example egress restriction using iptables on the Langfuse host
iptables -A OUTPUT -m owner --uid-owner langfuse -d 169.254.169.254 -j REJECT
iptables -A OUTPUT -m owner --uid-owner langfuse -d 10.0.0.0/8 -j REJECT
iptables -A OUTPUT -m owner --uid-owner langfuse -d 172.16.0.0/12 -j REJECT
iptables -A OUTPUT -m owner --uid-owner langfuse -d 192.168.0.0/16 -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.