CVE-2025-63388
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/12/2025
Last modified:
28/01/2026
Description
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:* |
To consult the complete list of CPE names with products and versions, see this page



