← Back to CVE List
Vulnerability Intelligence Report
Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint

CVE-2025-67732

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited quotas. Version 1.11.0 fixes the issue.

No Active Exploit Signals
CVSS Base Score
8.4
HIGH
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-200 ↗CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-522 ↗CWE-522: Insufficiently Protected Credentials

Affected Products & Versions

Vendor Product Affected Versions
langgenius dify < 1.11.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.305%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2025-12-10T20:04:28
Published2026-01-05T21:41:01
Last Updated2026-01-06T17:39:15

LINK COPIED TO CLIPBOARD