Vulnerability Intelligence Report
CVE-2025-63388
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoint implements an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true, allowing any external domain to make authenticated cross-origin requests. NOTE: the Supplier disputes this, providing the rationale of "sending requests with credentials does not provide any additional access compared to unauthenticated requests."
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
EPSS Probability:0.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-346 ↗CWE-346 Origin Validation Error
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| langgenius | dify | 1.9.1 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.200%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2025-10-27T00:00:00 |
| Published | 2025-12-18T00:00:00 |
| Last Updated | 2026-01-28T16:07:53 |
Community Chatter & Buzz