CVE-2025-63388

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
28/01/2026

Description

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:*