Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities to inject malicious script code into web pages. This may result in a cross-site scripting (XSS) attack when a user browses these web pages. At time of posting, there is no known patched version.
History

Wed, 18 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 22:45:00 +0000

Type Values Removed Values Added
Description Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities to inject malicious script code into web pages. This may result in a cross-site scripting (XSS) attack when a user browses these web pages. At time of posting, there is no known patched version.
Title Dify has XSS vulnerability
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-17T22:34:24.515Z

Updated: 2025-06-18T13:39:29.065Z

Reserved: 2025-06-02T10:39:41.635Z

Link: CVE-2025-49149

cve-icon Vulnrichment

Updated: 2025-06-18T13:39:23.476Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T23:15:30.570

Modified: 2025-06-18T13:46:52.973

Link: CVE-2025-49149

cve-icon Redhat

No data.