XSS Vulnerability in langgenius/dify Affects Firefox Browsers
CVE-2025-3467

8HIGH

Key Information:

Vendor

Langgenius

Vendor
CVE Published:
7 July 2025

What is CVE-2025-3467?

A vulnerability exists within langgenius/dify that affects certain versions when accessed through Firefox browsers. This Cross-Site Scripting (XSS) flaw enables attackers to execute malicious scripts, thereby capturing the administrator's token via payloads sent in published chats. When the administrator subsequently views this chat content through the monitoring feature, the malicious script triggers, potentially leading to the unauthorized disclosure of sensitive token information.

Affected Version(s)

langgenius/dify < 1.1.3

References

CVSS V3.0

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3467 : XSS Vulnerability in langgenius/dify Affects Firefox Browsers