---
title: Vulnerability Handling
description: How we handle security vulnerabilities through manual reports and automated detection.
---

# Vulnerability Handling

We have two different processes for handling security reports. These security reports are always triaged by engineers within 24 hours to act on them promptly if needed.

## Process 1: Manual security reports

Manual vulnerability reports should be submitted through the [ClickHouse Bugcrowd program](https://bugcrowd.com/engagements/clickhouse). Engineering triages Langfuse submissions and creates a Linear ticket in the Vulnerability Dashboard. If a report arrives through support or email, direct the reporter to Bugcrowd rather than requesting sensitive proof-of-concept details in those channels. For reports that suggest active exploitation or customer data exposure, also page engineering on Slack `#security` immediately.

```mermaid
flowchart LR
    Reporter["Security Researcher/Customer/Team"] --> Bugcrowd["ClickHouse Bugcrowd Program"]
    Bugcrowd --> Triage["Engineer Triages Langfuse Submission"]
    Triage --> Linear["Engineer Creates Linear Ticket (Vulnerability Dashboard)"]
```

## Process 2: Automated Vulnerability Detection

All Langfuse repositories have Dependabot and Snyk enabled. Vulnerabilities are automatically reported to GitHub, which sends webhooks to Make.com to create Linear tickets and auto-assign to the respective engineer.

```mermaid
flowchart TD
    subgraph Repos["Code Repositories"]
        direction TB
        Dependabot["Dependabot"]
        Snyk["Snyk"]
    end

    Dependabot --> GitHub["GitHub Security Alerts"]
    Snyk --> GitHub

    GitHub --> Make["Webhook to Make.com"]
    Make --> Linear["Linear Ticket<br/>(Vulnerability Dashboard)"]
    Linear --> Route{"Route by<br/>Repository Type"}

    Route -->|SDK Repository| SDKEngineer["Auto-assign to<br/>SDK Engineer"]
    Route -->|Other Repository| ProductEngineer["Auto-assign to<br/>Product Engineer"]

    SDKEngineer --> Triage1["Engineer Triages"]
    ProductEngineer --> Triage2["Engineer Triages"]
```

<!-- agent-instructions -->

---

## Agent Instructions

This page is part of the [Langfuse](https://langfuse.com) documentation, published as plain Markdown for AI agents. Every page is available as Markdown by appending `.md` to its URL, or by sending an `Accept: text/markdown` header. This page: `https://langfuse.com/handbook/product-engineering/playbooks/vulnerability-handling.md`.

### Querying these docs

If the answer is not on this page, query the documentation instead of guessing:

- **Semantic search** across all Langfuse docs, returning an answer with the relevant pages and excerpts. Ask a specific, self-contained question:

  ```bash
  curl -sG "https://langfuse.com/api/search-docs" --data-urlencode "query=How do I trace a LangGraph agent?"
  ```

- **Index of every page**: <https://langfuse.com/llms.txt>, with per-section indexes [llms-docs.txt](https://langfuse.com/llms-docs.txt), [llms-integrations.txt](https://langfuse.com/llms-integrations.txt), and [llms-self-hosting.txt](https://langfuse.com/llms-self-hosting.txt).

### Before writing Langfuse code

- **Install the [Langfuse Agent Skill](https://langfuse.com/docs/api-and-data-platform/features/agent-skill).** It encodes Langfuse's own best practices for instrumentation, prompt management, and evaluation, and materially improves results.
- **Read [What does a good trace look like?](https://langfuse.com/docs/observability/best-practices.md)** before instrumenting an application.
- **Verify endpoints, parameters, and response fields** against the [API reference](https://api.reference.langfuse.com) instead of inferring them from code examples.
- **Use the [Langfuse CLI](https://langfuse.com/docs/api-and-data-platform/features/cli)** (`npx langfuse-cli api <resource> <action>`) to read or write traces, prompts, datasets, and scores from the terminal.

Found an error in these docs? Please open an issue at <https://github.com/langfuse/langfuse-docs/issues>.
