Dify

Dify

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 05.01.2026 21:41:01
  • Zuletzt bearbeitet 12.01.2026 18:20:15

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, po...

  • EPSS 0.02%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 28.01.2026 17:16:07

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-...

  • EPSS 0.02%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 22.01.2026 18:16:42

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentia...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 29.01.2026 18:16:07

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) expos...

  • EPSS 16.71%
  • Veröffentlicht 18.12.2025 00:00:00
  • Zuletzt bearbeitet 22.01.2026 20:16:09

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement ...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 30.09.2025 17:15:41
  • Zuletzt bearbeitet 07.10.2025 13:20:03

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 14.04.2025 00:00:00
  • Zuletzt bearbeitet 18.06.2025 13:40:32

Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 20.03.2025 10:09:14
  • Zuletzt bearbeitet 01.04.2025 20:35:15

langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allowing an attacker to make direct requests to internal network services. Thi...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 20.03.2025 10:09:11
  • Zuletzt bearbeitet 27.03.2025 19:18:14

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does no...