PT-2025-17294 · Dify · Dify
H0J3N
+1
·
Published
2025-04-18
·
Updated
2025-04-18
·
CVE-2025-32790
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Dify versions 0.6.8 and prior
Description
A vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in "/export" should only allow administrator users to export DSL.
Recommendations
For versions 0.6.8 and prior, update the access control mechanisms to enforce stricter user role permissions and implement role-based access controls (RBAC) to ensure that only users with admin privileges can export the APP DSL.
Update to version 0.6.13 to fix the vulnerability.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dify