How An Authorization Flaw Reveals A Common Security Blind Spot: CVE-2025-59305 Case Study
depthfirst.com | vulnerability | High | CVE-2025-59305 | #ai-security | #vulnerability-research | #access-control | #authorization | #langfuse | #cve-2025-59305 | #llm-platform
Summary
A missing authorization check in Langfuse's background job controls let any authenticated user restart data migrations, risking data corruption and platform-wide DoS; tracked as CVE-2025-59305.
- CVSS
- 7.6
- Published
- Collected
Skip to content