PT-2025-17294 · Dify · Dify

H0J3N

+1

·

Published

2025-04-18

·

Updated

2025-04-18

·

CVE-2025-32790

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Dify versions 0.6.8 and prior
Description A vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in "/export" should only allow administrator users to export DSL.
Recommendations For versions 0.6.8 and prior, update the access control mechanisms to enforce stricter user role permissions and implement role-based access controls (RBAC) to ensure that only users with admin privileges can export the APP DSL. Update to version 0.6.13 to fix the vulnerability.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-32790
GHSA-JP6M-V4GW-5VGP

Affected Products

Dify