SB2025042855 - Improper Restriction of Rendered UI Layers or Frames in Dify



SB2025042855 - Improper Restriction of Rendered UI Layers or Frames in Dify

Published: April 28, 2025 Updated: July 28, 2026

Security Bulletin ID SB2025042855
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2025-43854)

CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to trick users into performing unauthorized actions.

The vulnerability exists due to improper restriction of rendered ui layers or frames in the web interface when rendering application pages inside a frame or iframe. A remote attacker can embed the application in a crafted webpage to trick users into performing unauthorized actions.

User interaction is required.


Remediation

Install update from vendor's website.