CVE-2025-49149
- EPSS 0.04%
- Veröffentlicht 17.06.2025 22:34:24
- Zuletzt bearbeitet 01.08.2025 22:13:08
Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities to inject malicious script code into web pages. This may result in a c...
CVE-2025-43854
- EPSS 0.04%
- Veröffentlicht 28.04.2025 15:58:54
- Zuletzt bearbeitet 12.05.2025 19:37:01
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page witho...
CVE-2025-43862
- EPSS 0.09%
- Veröffentlicht 25.04.2025 15:05:32
- Zuletzt bearbeitet 01.08.2025 22:00:11
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allow...
CVE-2025-32796
- EPSS 0.11%
- Veröffentlicht 18.04.2025 16:15:23
- Zuletzt bearbeitet 30.04.2025 16:12:32
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and norm...
CVE-2025-32795
- EPSS 0.07%
- Veröffentlicht 18.04.2025 16:15:23
- Zuletzt bearbeitet 19.06.2025 00:25:59
Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows ...
CVE-2025-32790
- EPSS 0.08%
- Veröffentlicht 18.04.2025 12:15:11
- Zuletzt bearbeitet 19.06.2025 00:36:04
Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow admini...
CVE-2025-29720
- EPSS 0.02%
- Veröffentlicht 14.04.2025 00:00:00
- Zuletzt bearbeitet 18.06.2025 13:40:32
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
CVE-2025-0184
- EPSS 0.12%
- Veröffentlicht 20.03.2025 10:11:38
- Zuletzt bearbeitet 15.07.2025 15:41:34
A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If an external relationship exists in the DOCX file, the reltyp...
CVE-2024-11850
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:10:55
- Zuletzt bearbeitet 15.07.2025 16:00:30
A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can expl...
CVE-2024-12776
- EPSS 0.16%
- Veröffentlicht 20.03.2025 10:10:42
- Zuletzt bearbeitet 14.07.2025 18:18:36
In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the ...