Skip to content

Instantly share code, notes, and snippets.

@Cristliu
Created January 21, 2026 17:31
Show Gist options
  • Select an option

  • Save Cristliu/c2bc7d05abd89db8eb542a453a528d77 to your computer and use it in GitHub Desktop.

Select an option

Save Cristliu/c2bc7d05abd89db8eb542a453a528d77 to your computer and use it in GitHub Desktop.
CVE-2025-63388 Public Disclosure

Security Advisory: CVE-2025-63388 - CORS Misconfiguration in Dify System Features Endpoint

CVE ID: CVE-2025-63388 Date: 2025-12-18 Vendor: LangGenius (Dify) Product: Dify Affected Versions: v1.9.1 Vulnerability Type: Insecure Permissions / CORS Misconfiguration Severity: Medium (Information Disclosure)

Summary

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true.

Impact

  • Information Disclosure: Attackers can retrieve sensitive system configuration information via malicious cross-origin requests.

References

Credits

Discovered by Zhihuang Liu (herecristliu@gmail.com).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment