Insufficiently protected credentials in Dify - CVE-2025-67732
Published: July 27, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to insufficiently protected credentials in the /console/api/workspaces/current/model-providers endpoint when returning model provider configuration data. A remote user can inspect the endpoint response to disclose sensitive information.
Exploitation requires access to the frontend or its network responses, and exposed credentials may belong to administrator-managed third-party service accounts.