PT-2025-39319 · Langfuse · Langfuse

Published

2025-09-24

·

Updated

2026-01-28

·

CVE-2025-59305

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Langfuse versions prior to d67b317
Description An improper authorization issue exists in the background migration endpoints of Langfuse. Any authenticated user can invoke migration control functions, potentially leading to data corruption or denial of service. This is due to unauthorized access to TRPC endpoints, including backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
Recommendations Versions prior to d67b317 should be updated to d67b317 or later.

Exploit

Fix

DoS

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-59305

Affected Products

Langfuse