Authorization bypass through user-controlled key in Dify - #VU144401
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to modify MCP server configurations belonging to other applications in the same workspace.
The vulnerability exists due to improper access control in AppMCPServerController.put() when handling PUT requests to /console/api/apps/
The issue affects applications within the same workspace.