Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app details, despite being restricted from viewing apps, which poses a security risk to the integrity of the application. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can modify app details.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-11859 Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app details, despite being restricted from viewing apps, which poses a security risk to the integrity of the application. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can modify app details.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Jun 2025 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Langgenius
Langgenius dify
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:*
Vendors & Products Langgenius
Langgenius dify

Fri, 18 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app details, despite being restricted from viewing apps, which poses a security risk to the integrity of the application. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can modify app details.
Title Dify Allows Insecure User Role Access Control for APP Editing
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-18T16:37:49.329Z

Reserved: 2025-04-10T12:51:12.281Z

Link: CVE-2025-32795

cve-icon Vulnrichment

Updated: 2025-04-18T16:37:44.470Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-18T16:15:23.627

Modified: 2025-06-19T00:25:59.333

Link: CVE-2025-32795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.