Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fxv-w47f-g229

Опубликовано: 02 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 1.3
CVSS3: 5

Описание

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

EPSS

Процентиль: 9%
0.00031
Низкий

1.3 Low

CVSS4

5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5
nvd
5 месяцев назад

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

EPSS

Процентиль: 9%
0.00031
Низкий

1.3 Low

CVSS4

5 Medium

CVSS3

Дефекты

CWE-918