DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0.
History

Mon, 28 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0.
Title DIFY vulnerable to Clickjacking Attack
Weaknesses CWE-1021
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-28T15:58:54.689Z

Updated: 2025-04-28T18:07:31.146Z

Reserved: 2025-04-17T20:07:08.555Z

Link: CVE-2025-43854

cve-icon Vulnrichment

Updated: 2025-04-28T18:07:19.162Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-28T16:15:33.043

Modified: 2025-04-29T13:52:10.697

Link: CVE-2025-43854

cve-icon Redhat

No data.