SB2025042855 - Improper Restriction of Rendered UI Layers or Frames in Dify
Published: April 28, 2025 Updated: July 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2025-43854)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote attacker to trick users into performing unauthorized actions.
The vulnerability exists due to improper restriction of rendered ui layers or frames in the web interface when rendering application pages inside a frame or iframe. A remote attacker can embed the application in a crafted webpage to trick users into performing unauthorized actions.
User interaction is required.
Remediation
Install update from vendor's website.