VYPR
High severity7.6NVD Advisory· Published Sep 24, 2025· Updated Jun 17, 2026

CVE-2025-59305

CVE-2025-59305

Description

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Langfuse/Langfuse3 versions
    cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*range: >=3.1.0,<3.109.0
    • (no CPE)
    • (no CPE)range: < d67b317

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.