Server Manipulation Vulnerability in Dify Open-Source LLM App Development Platform
CVE-2026-105761

7.1HIGH

Key Information:

Vendor

Langgenius

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105761?

Dify, an open-source language model application development platform, had a vulnerability in its API before version 1.16.0. The vulnerability existed in the PUT /console/api/apps/<app_id>/server endpoint, which did not properly verify if the server ID provided by authenticated users was associated with the requested application and tenant. This oversight allowed an authenticated workspace member to change the status and parameters of another application's MCP server. Such a manipulation could lead to data redirection or service disruption. This issue has been addressed in version 1.16.0.

Affected Version(s)

dify < 1.16.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.