CVE-2025-32790
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 284
Summary
CVE-2025-32790: In earlier versions of Dify, a vulnerability was identified in the DIFY AI that granted normal users the ability to export App DSL, which should have been a feature restricted to administrator users. This flaw, located in the '/export' feature, can be mitigated by implementing stricter access control mechanisms and role-based access controls (RBAC) to ensure that only those with administrative privileges have the authority to export App DSL. This issue is rectified in version 0.6.13.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Dify