Improper access control in Dify - CVE-2025-43862
Published: April 25, 2025 / Updated: July 28, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote user to modify application orchestration and access sensitive information.
The vulnerability exists due to improper access control in the APP orchestration workflow endpoints when handling requests to /app/{app.id}/workflow and related paths. A remote user can send crafted requests to access and modify APP orchestration to modify application orchestration and access sensitive information.
The issue affects non-admin users who should not be able to access the orchestration interface, and exposed orchestration data may include embedded API keys and DSL workflow files.