CNNVD-202511-896 Information
CNNVD ID
CNNVD-202511-896
Related CVE
- CNNVD Published: 2025-11-10
Description (Chinese)
langfuse是Langfuse开源的一个大语言模型工程平台。 Langfuse 2.70.0版本至2.95.11之前版本和3.124.1之前版本存在安全漏洞,该漏洞源于服务器信任用户控制的orgId并用于授权检查,可能导致用户枚举其他组织成员信息。
Description (English)
langfuse is a large-language modelling platform for the Langfuse open source. There is a security loophole in the Langfuse 2.70.0 to 2.95.11 and 3.124.1 versions, which originates from the server trusting in the user-controlled orgId and is used to authorize inspection, which may result in the user enumerating other organization members.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Langfuse
Published
2025-11-10
Last Modified
2026-02-24
References
https://github.com/langfuse/langfuse/security/advisories/GHSA-94hf-6gqq-pj69 https://github.com/langfuse/langfuse/commit/6c2529049a4c962928c435984c81a547a497e3e5 https://github.com/langfuse/langfuse/releases/tag/v3.124.1 https://github.com/langfuse/langfuse/releases/tag/v2.95.11 https://github.com/langfuse/langfuse/releases/tag/v2.70.0 https://github.com/langfuse/langfuse/commit/67990ebfdcf0f0c32a6710efa7ddbda073812ab4 https://access.redhat.com/security/cve/cve-2025-64504
Patch
https://github.com/langfuse/langfuse/releases
Share on: