Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langfuse
Langfuse langfuse |
|
| Vendors & Products |
Langfuse
Langfuse langfuse |
Fri, 21 Nov 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_<PROVIDER>_CHECK setting, a potential account takeover may happen if an authenticated user is made to call a specifically crafted URL via a CSRF or phishing attack. This issue has been patched in versions 2.95.12 and 3.131.0. A workaround for this issue involves setting AUTH_<PROVIDER>_CHECK. | |
| Title | Langfuse SSO Account Takeover via CSRF or phishing attack | |
| Weaknesses | CWE-285 CWE-352 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-24T17:16:40.383Z
Reserved: 2025-11-17T20:55:34.694Z
Link: CVE-2025-65107
Updated: 2025-11-24T17:16:35.234Z
Status : Awaiting Analysis
Published: 2025-11-21T22:16:33.127
Modified: 2025-11-25T22:16:42.557
Link: CVE-2025-65107
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:08:28Z