Improper access control in Dify - CVE-2025-32795
Published: April 18, 2025 / Updated: July 28, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote user to modify app details.
The vulnerability exists due to improper access control in the app editing endpoints when handling authenticated requests to update app names, descriptions, and icons. A remote user can send a crafted request to modify app details.
Normal users are able to perform edit actions even though they are restricted from viewing apps.