Dify
9 known vulnerabilities
Top Products
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set
Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<ap
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rend
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi
Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been foun
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the
Frequently Asked Questions
How many CVEs affect Dify?
Dify has 9 CVE records in our database, including 2 critical and 1 high severity vulnerabilities.
What are the most severe Dify vulnerabilities?
Dify has 2 critical severity (CVSS 9.0+) and 1 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Dify vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Dify products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Dify Vulnerabilities
CyberStrike scans your infrastructure for Dify vulnerabilities and provides real-time remediation guidance.
Get Started