More information about this CVE will likely be available in a few days

Description


A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests.

Related CPE's


Could not find any relations

Weaknesses


Could not find any weaknesses

CVSS impact metrics


Could not find any metrics

Information


Source identifier

[email protected]

Vulnerability status

Undergoing analysis

Published

2025-12-18T16:15:54.650

28 hours ago

Last modified

2025-12-19T18:00:54.283

3 hours ago