Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Improper authorization in the background migration endpoints of Langfuse 3.1 before d67b317 allows any authenticated user to invoke migration control functions. This can lead to data corruption or denial of service through unauthorized access to TRPC endpoints such as backgroundMigrations.all, backgroundMigrations.status, and backgroundMigrations.retry.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
langfuse 安全漏洞
Vulnerability Description
langfuse是Langfuse开源的一个大语言模型工程平台。 langfuse存在安全漏洞,该漏洞源于背景迁移端点授权不当,可能导致数据损坏或拒绝服务攻击。
CVSS Information
N/A
Vulnerability Type
N/A