Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-64504

Опубликовано: 10 нояб. 2025
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2.95.11 and 3.124.1, in certain project membership APIs, the server trusted a user‑controlled orgId and used it in authorization checks. As a result, any authenticated user on the same Langfuse instance could enumerate names and email addresses of users in another organization if they knew the target organization’s ID. Disclosure is limited to names and email addresses of members/invitees. No customer data such as traces, prompts, or evaluations is exposed or accessible. For Langfuse Cloud, the maintainers ran a thorough investigation of access logs of the last 30 days and could not find any evidence that this vulnerability was exploited. For most self-hosting deployments, the attack surface is significantly reduced given an SSO provider is configured and email/password sign-up is disabled. In these cases, only users who authenticate via the Enterprise SSO IdP (e.g

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*
Версия от 2.70.0 (включая) до 2.95.11 (исключая)
cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.124.1 (исключая)

EPSS

Процентиль: 24%
0.00083
Низкий

5 Medium

CVSS3

Дефекты

CWE-202

EPSS

Процентиль: 24%
0.00083
Низкий

5 Medium

CVSS3

Дефекты

CWE-202