Access Control Flaw in Dify LLM App Development Platform
CVE-2025-59422

6MEDIUM

Key Information:

Vendor

Langgenius

Status
Vendor
CVE Published:
25 September 2025

What is CVE-2025-59422?

A vulnerability in Dify, an open-source LLM application development platform, allows users within the same workspace to access chat messages from other users via the specific API endpoint. Regular users can exploit this weakness to view sensitive information, including messages from admins and other users, provided they have knowledge of the conversation_id. This breach compromises the confidentiality of conversations. The issue has been addressed in version 1.9.0 of Dify.

Affected Version(s)

dify = 1.8.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59422 : Access Control Flaw in Dify LLM App Development Platform