- CVSS
- MEDIUM · 6.5v3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Published
- 2025-11-21
- Weakness
- CWE-285, CWE-352
- Source
- nvd.nist.gov/vuln/detail/CVE-2025-65107
Description
Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from 3.17.0 to before 3.131.0, in SSO provider configurations without an explicit AUTH_
References
How GTK Cyber trains on this
AI security training at GTK Cyber covers the LLM and ML-pipeline vulnerability classes that vulnerabilities like CVE-2025-65107 fall into. Our hands-on courses are taught by Charles Givre and other practitioners who break and defend production AI systems.