VendorsLangGeniusdifyall versions
Vulnerabilities

LangGenius Dify

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2025-56157
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
Published 2025-12-18 · Modified
9.8EPSS 0.009
CVE-2025-3466
Unsanitized Input in langgenius/dify
Published 2025-07-07 · Analyzed
9.8EPSS 0.007
CVE-2025-63386
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration is intentional to support bootstrap.
Published 2025-12-18 · Modified
9.1EPSS 0.002
CVE-2025-63388
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."
Published 2025-12-18 · Modified
9.1EPSS 0.002
CVE-2024-10252
Code Injection in langgenius/dify
Published 2025-03-20 · Analyzed
8.8EPSS 0.008
CVE-2025-1796
Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in langgenius/dify
Published 2025-03-20 · Analyzed
8.8EPSS 0.006
CVE-2024-12039
Improper Restriction of Excessive Authentication Attempts in langgenius/dify
Published 2025-03-20 · Analyzed
8.1EPSS 0.007
CVE-2024-12776
Authentication Bypass in langgenius/dify
Published 2025-03-20 · Analyzed
8.1EPSS 0.007
CVE-2025-3467
XSS Vulnerability in langgenius/dify
Published 2025-07-07 · Analyzed
8.0EPSS 0.003
CVE-2024-11824
Stored XSS in langgenius/dify
Published 2025-03-20 · Analyzed
7.6EPSS 0.005
CVE-2025-43862
Dify Allows Unauthorized Access and Modification of APP Orchestration
Published 2025-04-25 · Analyzed
7.6EPSS 0.003
CVE-2025-63387
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed.
Published 2025-12-18 · Modified
7.5EPSS 0.299
CVE-2026-42138
Dify Vulnerable to Stored XSS via SVG-file upload
Published 2026-05-04 · Analyzed
6.9EPSS 0.003
CVE-2024-11850
Stored XSS in langgenius/dify
Published 2025-03-20 · Analyzed
6.8EPSS 0.004
CVE-2024-12775
SSRF in langgenius/dify
Published 2025-03-20 · Analyzed
6.5EPSS 0.006
CVE-2025-0184
Server-Side Request Forgery (SSRF) in langgenius/dify
Published 2025-03-20 · Analyzed
6.5EPSS 0.005
CVE-2026-41950
Dify < 1.14.0 Authorization Bypass via File UUID
Published 2026-05-05 · Modified
6.5EPSS 0.005
CVE-2025-32796
Dify Allows Unauthorized APP Enable/Disable via API
Published 2025-04-18 · Analyzed
6.5EPSS 0.004
CVE-2025-32795
Dify Allows Insecure User Role Access Control for APP Editing
Published 2025-04-18 · Analyzed
6.5EPSS 0.003
CVE-2025-32790
Dify Allows Insecure User Role Access Control for APP DSL Exporting
Published 2025-04-18 · Analyzed
6.3EPSS 0.003
CVE-2025-58747
Dify MCP OAuth Flow Vulnerable to XSS
Published 2025-10-17 · Analyzed
6.1EPSS 0.057
CVE-2025-49149
Dify has XSS vulnerability
Published 2025-06-17 · Analyzed
6.1EPSS 0.003
CVE-2025-43854
DIFY vulnerable to Clickjacking Attack
Published 2025-04-28 · Analyzed
6.1EPSS 0.002
CVE-2025-59422
Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Others
Published 2025-09-25 · Analyzed
6.0EPSS 0.002
CVE-2025-11750
User Enumeration via Distinct Error Messages in langgenius/dify-web
Published 2025-10-22 · Analyzed
5.3EPSS 0.007
CVE-2025-29720
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
Published 2025-04-14 · Analyzed
4.8EPSS 0.002
CVE-2024-11821
Privilege Escalation in langgenius/dify
Published 2025-03-20 · Analyzed
4.3EPSS 0.005