CORS Misconfiguration Vulnerability in Dify by LangGenius
CVE-2025-63386

Currently unrated

Key Information:

Vendor

LangGenius

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-63386?

A misconfiguration in the Cross-Origin Resource Sharing (CORS) policy of Dify version 1.9.1 exposes the /console/api/setup endpoint to security risks. This vulnerability allows any external domain to be reflected in the Origin header and enables Access-Control-Allow-Credentials to be set to true. As a result, unauthorized external domains can make authenticated requests, potentially compromising user data and system integrity.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.