CVE-2025-32795
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-32795 is a vulnerability affecting the Dify open-source LLM app development platform prior to version 0.6.12. This issue involves improper access control, granting normal users the ability to edit app names, descriptions, and icons. This access is not intended for non-admin users, who are typically restricted from viewing apps. The vulnerability poses a security risk to the integrity of the applications by allowing unauthorized modification of app details. The issue has been resolved in version 0.6.12, and a workaround involves updating access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can modify app details.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Dify