Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-9799

Опубликовано: 01 сент. 2025
Источник: nvd
CVSS3: 5
CVSS2: 4.6
EPSS Низкий

Описание

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file web/src/features/prompts/server/routers/promptRouter.ts of the component Webhook Handler. Performing manipulation results in server-side request forgery. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.

EPSS

Процентиль: 14%
0.00046
Низкий

5 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-918

EPSS

Процентиль: 14%
0.00046
Низкий

5 Medium

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-918