CVE-2025-67732
- EPSS 0.04%
- Veröffentlicht 05.01.2026 21:41:01
- Zuletzt bearbeitet 12.01.2026 18:20:15
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, po...
CVE-2025-63388
- EPSS 0.02%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 28.01.2026 17:16:07
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-...
CVE-2025-63386
- EPSS 0.02%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 22.01.2026 18:16:42
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentia...
CVE-2025-56157
- EPSS 0.1%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 29.01.2026 18:16:07
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) expos...
CVE-2025-63387
- EPSS 16.71%
- Veröffentlicht 18.12.2025 00:00:00
- Zuletzt bearbeitet 22.01.2026 20:16:09
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement ...
CVE-2025-56520
- EPSS 0.59%
- Veröffentlicht 30.09.2025 17:15:41
- Zuletzt bearbeitet 07.10.2025 13:20:03
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.
CVE-2025-29720
- EPSS 0.02%
- Veröffentlicht 14.04.2025 00:00:00
- Zuletzt bearbeitet 18.06.2025 13:40:32
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
CVE-2024-11822
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:09:14
- Zuletzt bearbeitet 01.04.2025 20:35:15
langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allowing an attacker to make direct requests to internal network services. Thi...
CVE-2025-0185
- EPSS 0.88%
- Veröffentlicht 20.03.2025 10:09:11
- Zuletzt bearbeitet 27.03.2025 19:18:14
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does no...