CVE-2025-32795

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 284

Summary

CVE-2025-32795 is a vulnerability affecting the Dify open-source LLM app development platform prior to version 0.6.12. This issue involves improper access control, granting normal users the ability to edit app names, descriptions, and icons. This access is not intended for non-admin users, who are typically restricted from viewing apps. The vulnerability poses a security risk to the integrity of the applications by allowing unauthorized modification of app details. The issue has been resolved in version 0.6.12, and a workaround involves updating access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can modify app details.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share