XSS Vulnerability in langgenius/dify Affects Firefox Browsers
CVE-2025-3467
8HIGH
What is CVE-2025-3467?
A vulnerability exists within langgenius/dify that affects certain versions when accessed through Firefox browsers. This Cross-Site Scripting (XSS) flaw enables attackers to execute malicious scripts, thereby capturing the administrator's token via payloads sent in published chats. When the administrator subsequently views this chat content through the monitoring feature, the malicious script triggers, potentially leading to the unauthorized disclosure of sensitive token information.
Affected Version(s)
langgenius/dify < 1.1.3