Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31045 | Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 17 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Finto
Finto langfuse |
|
| CPEs | cpe:2.3:a:finto:langfuse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Finto
Finto langfuse |
Thu, 25 Sep 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 25 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 25 Sep 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langfuse
Langfuse langfuse |
|
| Vendors & Products |
Langfuse
Langfuse langfuse |
Wed, 24 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-285 | |
| Metrics |
cvssV3_1
|
Wed, 24 Sep 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-25T16:29:09.850Z
Reserved: 2025-09-12T00:00:00.000Z
Link: CVE-2025-59305
Updated: 2025-09-24T19:42:22.957Z
Status : Analyzed
Published: 2025-09-24T18:15:42.107
Modified: 2025-10-17T14:54:41.870
Link: CVE-2025-59305
No data.
OpenCVE Enrichment
Updated: 2025-09-25T08:22:02Z
EUVD