Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-65107

Опубликовано: 21 нояб. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_CHECK setting, a potential account takeover may happen if an authenticated user is made to call a specifically crafted URL via a CSRF or phishing attack. This issue has been patched in versions 2.95.12 and 3.131.0. A workaround for this issue involves setting AUTH_CHECK.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*
Версия от 2.95.0 (включая) до 2.95.12 (исключая)
cpe:2.3:a:langfuse:langfuse:*:*:*:*:*:*:*:*
Версия от 3.17.0 (включая) до 3.131.0 (исключая)

EPSS

Процентиль: 6%
0.00023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285

EPSS

Процентиль: 6%
0.00023
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-285