Skip to main content

Vendor/product archive

langgenius / dify CVEs

Beta · best-effort

27 CVEs tagged to langgenius / dify3 Critical, 8 High, 14 Medium, 2 Low, 0 Unrated.

CVE-2026-41950

Published May 5, 2026

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the sam…

CVSS 6.0 · Medium
evidence mentions
6
Buzz score
35.5
Vendor/product tagsBeta · best-effort

CVE-2026-42138

Published May 4, 2026

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. Th…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-63387

Published Dec 18, 2025

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56157

Published Dec 18, 2025

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-63388

Published Dec 18, 2025

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permiss…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-63386

Published Dec 18, 2025

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy tha…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-11750

Published Oct 22, 2025

In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accou…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58747

Published Oct 17, 2025

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects to an attacke…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59422

Published Sep 25, 2025

Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVER…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3467

Published Jul 7, 2025

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator'…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3466

Published Jul 7, 2025

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability ar…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49149

Published Jun 17, 2025

Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-43854

Published Apr 28, 2025

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing maliciou…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-43862

Published Apr 25, 2025

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestra…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32796

Published Apr 18, 2025

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32795

Published Apr 18, 2025

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to e…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32790

Published Apr 18, 2025

Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissio…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-29720

Published Apr 14, 2025

Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1796

Published Mar 20, 2025

A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0184

Published Mar 20, 2025

A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-12776

Published Mar 20, 2025

In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including admin…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12775

Published Mar 20, 2025

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /cons…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12039

Published Mar 20, 2025

langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11850

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input i…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11824

Published Mar 20, 2025

A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HT…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2