Authentication Bypass in Dify Web by Langgenius
CVE-2025-11750
What is CVE-2025-11750?
In Dify Web version 1.6.0, the authentication mechanism is flawed as it differentiates between error messages for non-existent and existing user accounts. When a user attempts to log in or register using an invalid username or email, the system displays a message indicating the account is not found. However, for accounts that exist but have an incorrect password, a different error message is generated. This inconsistency allows attackers to identify valid user accounts, creating opportunities for social engineering, brute force, or credential stuffing attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
langgenius/dify <= unspecified
References
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
