PT-2025-39319 · Langfuse · Langfuse
CVE-2025-59305
·
Publicado
2025-09-24
·
Atualizado
2026-01-28
CVSS v3.1
7.6
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Langfuse versions prior to d67b317
Description
An improper authorization issue exists in the background migration endpoints of Langfuse. Any authenticated user can invoke migration control functions, potentially leading to data corruption or denial of service. This is due to unauthorized access to TRPC endpoints, including
backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.Recommendations
Versions prior to d67b317 should be updated to d67b317 or later.
Exploit
Correção
DoS
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Langfuse