« Volver al listado

CVE-2025-63387

Estado: ModificadaAlta (7.5)—

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:N acceso remoto sin autenticación a endpoint /console/api/system-features; acceso a datos de configuración del sistema (T1526: enumeration de recursos cloud/sistema).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-63387",
  "cveTags": [
    {
      "tags": [
        "disputed"
      ],
      "sourceIdentifier": "cve@mitre.org"
    }
  ],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-63387",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-19T17:32:01.989880Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-18T19:16:33.157",
  "references": [
    {
      "url": "https://gist.github.com/Cristliu/cddc0cbbf354de51106ab63a11be94af",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gist.github.com/Cristliu/dfc5f3a31dc6d7fff2754867e5c649a5",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/langgenius/dify/discussions",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/langgenius/dify/issues/31368#issuecomment-3783712203",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/langgenius/dify/pull/31392",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/langgenius/dify/pull/31417",
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed."
    },
    {
      "lang": "es",
      "value": "Dify v1.9.1 es vulnerable a Permisos Inseguros. Un atacante no autenticado puede enviar directamente solicitudes HTTP GET al endpoint /console/api/system-features sin ninguna credencial de autenticación o tokens de sesión. El endpoint no implementa controles de autorización adecuados, permitiendo el acceso anónimo a datos sensibles de configuración del sistema. NOTA: El mantenedor afirma que el endpoint no está autenticado por diseño y sirve como un mecanismo de arranque requerido para la inicialización del panel de control. También afirman que la descripción clasifica de forma imprecisa los datos devueltos como configuración sensible del sistema, afirmando que los datos no son sensibles y son requeridos para la renderización del lado del cliente. No se exponen PII, credenciales o secretos."
    }
  ],
  "lastModified": "2026-10-05T18:10:00.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABF9FC69-C390-446E-830C-5F8B0A0488F2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}