Server Manipulation Vulnerability in Dify Open-Source LLM App Development Platform
CVE-2026-105761
7.1HIGH
What is CVE-2026-105761?
Dify, an open-source language model application development platform, had a vulnerability in its API before version 1.16.0. The vulnerability existed in the PUT /console/api/apps/<app_id>/server endpoint, which did not properly verify if the server ID provided by authenticated users was associated with the requested application and tenant. This oversight allowed an authenticated workspace member to change the status and parameters of another application's MCP server. Such a manipulation could lead to data redirection or service disruption. This issue has been addressed in version 1.16.0.
Affected Version(s)
dify < 1.16.0
