SB2025041768 - Improper access control in Dify



SB2025041768 - Improper access control in Dify

Published: April 17, 2025 Updated: July 28, 2026

Security Bulletin ID SB2025041768
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2025-32790)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in /console/api/apps/{app.id}/export when handling export requests for APP DSL files. A remote user can send a request to export an application's DSL to disclose sensitive information.

The issue affects normal user accounts that should not be permitted to export APP DSL intended for administrator team members.


Remediation

Install update from vendor's website.