VYPR
Unrated severityNVD Advisory· Published Sep 24, 2025· Updated Sep 25, 2025

CVE-2025-59305

CVE-2025-59305

Description

Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Langfuse/Langfusecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=3.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.