Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
History

Fri, 17 Oct 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Finto
Finto langfuse
CPEs cpe:2.3:a:finto:langfuse:*:*:*:*:*:*:*:*
Vendors & Products Finto
Finto langfuse

Thu, 25 Sep 2025 17:30:00 +0000


Thu, 25 Sep 2025 16:45:00 +0000


Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Langfuse
Langfuse langfuse
Vendors & Products Langfuse
Langfuse langfuse

Wed, 24 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-09-24T00:00:00.000Z

Updated: 2025-09-25T16:29:09.850Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59305

cve-icon Vulnrichment

Updated: 2025-09-24T19:42:22.957Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-24T18:15:42.107

Modified: 2025-10-17T14:54:41.870

Link: CVE-2025-59305

cve-icon Redhat

No data.