Improper access control in Dify - #VU139798

 

Improper access control in Dify - #VU139798

Published: July 27, 2026


Vulnerability identifier: #VU139798
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LangGenius
Affected software:
Dify

Detailed vulnerability description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in the dataset creation and retrieval flows when handling dataset creation and update requests with an external_knowledge_api_id. A remote user can submit a dataset creation request using another tenant's external_knowledge_api_id to disclose sensitive information.

The attacker-owned dataset can become bound to a victim external API template, exposing victim endpoint metadata in the dataset response.


Remediation

Install security update from vendor's website.

Sources