SB20260727380 - Multiple vulnerabilities in Dify



SB20260727380 - Multiple vulnerabilities in Dify

Published: July 27, 2026

Security Bulletin ID SB20260727380
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the /use-check endpoint when handling requests for external API usage checks. A remote user can send a request for another tenant's external API template UUID to disclose sensitive information.

The issue can reveal whether a target external API template is in use and how many datasets reference it across tenants.


2) Improper access control (CVE-ID: N/A)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the dataset creation and retrieval flows when handling dataset creation and update requests with an external_knowledge_api_id. A remote user can submit a dataset creation request using another tenant's external_knowledge_api_id to disclose sensitive information.

The attacker-owned dataset can become bound to a victim external API template, exposing victim endpoint metadata in the dataset response.


Remediation

Install update from vendor's website.