Improper Restriction of Rendered UI Layers or Frames in Dify - CVE-2025-43854

 

Improper Restriction of Rendered UI Layers or Frames in Dify - CVE-2025-43854

Published: April 28, 2025 / Updated: July 28, 2026


Vulnerability identifier: #VU139832
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-43854
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LangGenius
Affected software:
Dify

Detailed vulnerability description

The vulnerability allows a remote attacker to trick users into performing unauthorized actions.

The vulnerability exists due to improper restriction of rendered ui layers or frames in the web interface when rendering application pages inside a frame or iframe. A remote attacker can embed the application in a crafted webpage to trick users into performing unauthorized actions.

User interaction is required.


How to mitigate CVE-2025-43854

Install security update from vendor's website.

Sources