Access Control Flaw in Dify LLM App Development Platform
CVE-2025-59422
6MEDIUM
What is CVE-2025-59422?
A vulnerability in Dify, an open-source LLM application development platform, allows users within the same workspace to access chat messages from other users via the specific API endpoint. Regular users can exploit this weakness to view sensitive information, including messages from admins and other users, provided they have knowledge of the conversation_id. This breach compromises the confidentiality of conversations. The issue has been addressed in version 1.9.0 of Dify.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dify = 1.8.1
References
CVSS V4
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
