PT-2025-52255 · Dify · Dify

Cristliu

·

Published

2025-12-18

·

Updated

2026-01-28

·

CVE-2025-63388

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Dify version 1.9.1
Description A Cross-Origin Resource Sharing (CORS) misconfiguration exists in the /console/api/system-features endpoint. The endpoint has an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials to true, potentially allowing any external domain to make authenticated cross-origin requests.
Recommendations Apply a restrictive CORS policy to the /console/api/system-features endpoint to only allow requests from trusted origins.

Fix

Origin Validation Error

Weakness Enumeration

Related Identifiers

CVE-2025-63388

Affected Products

Dify