langfuse kayıtları
langfuse üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control2
- CWE-285 Improper Authorization2
- CWE-202 Exposure of Sensitive Information Through Data Queries1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2025-59305İstismar yok | Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migratiolangfuse · langfuse · CWE-285 | Yüksek7,6 | — | %0,3 | 24 Eyl 2025 |
26İzleyin | CVE-2025-65107İstismar yok | Langfuse SSO Account Takeover via CSRF or phishing attacklangfuse · langfuse · CWE-285 | Orta6,5 | — | %0,2 | 21 Kas 2025 |
25İzleyin | CVE-2026-24055Kavram kanıtı | Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linkinglangfuse · langfuse · CWE-284 | Orta6,3 | — | %0,4 | 22 Oca 2026 |
21İzleyin | CVE-2026-41487İstismar yok | Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keyslangfuse · langfuse · CWE-284 | Orta5,3 | — | %0,3 | 8 May 2026 |
20İzleyin | CVE-2025-64504İstismar yok | Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIslangfuse · langfuse · CWE-202 | Orta5,0 | — | %0,3 | 10 Kas 2025 |
5İzleyin | CVE-2025-9799İstismar yok | Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgerylangfuse · langfuse · CWE-918 | Düşük1,3 | — | %0,3 | 1 Eyl 2025 |
- CVE-2025-5930530İzleyin
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migratio
YüksekCVSS 7,6İstismar yokEPSS %0langfuse · langfuse24 Eyl 2025
- CVE-2025-6510726İzleyin
Langfuse SSO Account Takeover via CSRF or phishing attack
OrtaCVSS 6,5İstismar yokEPSS %0langfuse · langfuse21 Kas 2025
- CVE-2026-2405525İzleyin
Langfuse Slack OAuth Installation Endpoint Lacks Authentication, Enabling Arbitrary Project Linking
OrtaCVSS 6,3Kavram kanıtıEPSS %0langfuse · langfuse22 Oca 2026
- CVE-2026-4148721İzleyin
Langfuse: Improper role-based-access control in Langfuse LLM connection management allowed users of role “member” to retrieve stored LLM provider API keys
OrtaCVSS 5,3İstismar yokEPSS %0langfuse · langfuse8 May 2026
- CVE-2025-6450420İzleyin
Langfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIs
OrtaCVSS 5,0İstismar yokEPSS %0langfuse · langfuse10 Kas 2025
- CVE-2025-97995İzleyin
Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery
DüşükCVSS 1,3İstismar yokEPSS %0langfuse · langfuse1 Eyl 2025