Improper access control in Dify - CVE-2025-32790

 

Improper access control in Dify - CVE-2025-32790

Published: April 17, 2025 / Updated: July 28, 2026


Vulnerability identifier: #VU139836
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-32790
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LangGenius
Affected software:
Dify

Detailed vulnerability description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in /console/api/apps/{app.id}/export when handling export requests for APP DSL files. A remote user can send a request to export an application's DSL to disclose sensitive information.

The issue affects normal user accounts that should not be permitted to export APP DSL intended for administrator team members.


How to mitigate CVE-2025-32790

Install security update from vendor's website.

Sources