CVE Vulnerabilities

CVE-2025-63388

Published: Dec 18, 2025 | Modified: Jan 28, 2026
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of sending requests with credentials does not provide any additional access compared to unauthenticated requests.

Affected Software

NameVendorStart VersionEnd Version
DifyLanggenius1.9.1 (including)1.9.1 (including)

References