Windows USB Video Driver - Out-of-bounds Read via Physical Attack
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-24055. PoCs published by imzanggg.
AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2026-24055, an improper access control vulnerability in Langfuse versions 3.89.0 to 3.146.0. The exploit demonstrates how an unauthenticated attacker can bind their Slack workspace to a victim's project via the `/api/public/slack/install` endpoint, leading to data leakage.
Description
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack.
Exploits (1)
This repository provides a functional proof-of-concept for CVE-2026-24055, an improper access control vulnerability in Langfuse versions 3.89.0 to 3.146.0. The exploit demonstrates how an unauthenticated attacker can bind their Slack workspace to a victim's project via the `/api/public/slack/install` endpoint, leading to data leakage.
References (1)
Scores
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N