CVE-2025-32790

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 284

Summary

CVE-2025-32790: In earlier versions of Dify, a vulnerability was identified in the DIFY AI that granted normal users the ability to export App DSL, which should have been a feature restricted to administrator users. This flaw, located in the '/export' feature, can be mitigated by implementing stricter access control mechanisms and role-based access controls (RBAC) to ensure that only those with administrative privileges have the authority to export App DSL. This issue is rectified in version 0.6.13.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share