CVE 9.1 CRITICAL

CVE-2025-63386_CVE-2025-63386

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests.

AI Analysis

CORS misconfiguration vulnerability in Dify v1.9.1

Basic Information

ID CVE-2025-63386
Source mitre
Published Dec 18, 2025 at 00:00
Modified Dec 19, 2025 at 21:24

Affected Product

Vendor langgenius
Product Dify
Version 1.9.1
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor langgenius
Product Dify
Version 1.9.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.