Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
History

Thu, 25 Sep 2025 17:30:00 +0000


Thu, 25 Sep 2025 16:45:00 +0000


Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Langfuse
Langfuse langfuse
Vendors & Products Langfuse
Langfuse langfuse

Wed, 24 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Description Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-09-25T16:29:09.850Z

Reserved: 2025-09-12T00:00:00.000Z

Link: CVE-2025-59305

cve-icon Vulnrichment

Updated: 2025-09-24T19:42:22.957Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-24T18:15:42.107

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-59305

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-25T08:22:02Z