Catalog / Dify

Dify security advisories

All 21 advisories Dify has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
2114 carry a CVE
high
8
medium
10
low
3
Fix in the archive
14of 21 matched to a release
Oldest
17 Apr 20251.4 years ago

7 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
GHSA-cg9f-q34p-p9h3low

Dify API Extension has SSRF Vulnerability

Fixed in 0.6.8, not held here
CVE-2026-26023high

Client‑side DOM XSS in the web chat app of Dify when using echarts

GHSA-qqjx-5h5w-x5vj
CVE-2025-59422medium

Broken Access Control on Log Message Endpoint Allows Reading Chats of Others

GHSA-jg5j-c9pq-w894Fixed in 1.9.0
CVE-2025-43854low

DIFY vulnerable to Clickjacking Attack

GHSA-jhgq-cx3f-vj5p
CVE-2025-43862high

Unauthorized Access and Modification of APP Orchestration

GHSA-6pw4-jqhv-3626
CVE-2025-32795medium

Insecure User Role Access Control for APP Editing

GHSA-gg5w-m2vw-vmmj
CVE-2025-32796medium

Unauthorized APP Enable/Disable via API

GHSA-hqcx-598m-pjq4
CVE-2025-32790medium

Insecure User Role Access Control for APP DSL Exporting

GHSA-jp6m-v4gw-5vgp