📦 Dify

by Dify

🔍 What is Dify?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0185

HIGH CVSS 8.8 Mar 20, 2025

This vulnerability in Dify Tools' Vanna module allows attackers to inject malicious queries through unsanitized user inputs, potentially leading to remote code execution. It affects systems using the ...

CVE-2024-11822

HIGH CVSS 7.5 Mar 20, 2025

This Server-Side Request Forgery (SSRF) vulnerability in langgenius/dify version 0.9.1 allows attackers to make unauthorized requests to internal network services by manipulating the api_endpoint para...

CVE-2026-26023

MEDIUM CVSS 6.1 Feb 11, 2026

This is a cross-site scripting (XSS) vulnerability in Dify's web chat frontend when using echarts. It allows attackers to execute arbitrary JavaScript code in users' browsers by injecting malicious pa...

CVE-2025-67732

MEDIUM CVSS 6.5 Jan 5, 2026

Dify versions before 1.11.0 expose API keys in plaintext to frontend users, allowing non-administrators to view and potentially misuse them. This vulnerability enables unauthorized access to third-par...

CVE-2025-56520

MEDIUM CVSS 5.3 Sep 30, 2025

Dify v1.6.0 contains a Server-Side Request Forgery (SSRF) vulnerability in the RemoteFileUploadApi component that allows attackers to make unauthorized requests from the server to internal or external...