CVE-2025-63387
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 30%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access75 % - Impacto principal
T1526Cloud Service Discoverydiscovery65 %
AV:N/PR:N acceso remoto sin autenticación a endpoint /console/api/system-features; acceso a datos de configuración del sistema (T1526: enumeration de recursos cloud/sistema).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-284
Referencias
- https://gist.github.com/Cristliu/cddc0cbbf354de51106ab63a11be94af
- https://gist.github.com/Cristliu/dfc5f3a31dc6d7fff2754867e5c649a5
- https://github.com/langgenius/dify/discussions
- https://github.com/langgenius/dify/issues/31368#issuecomment-3783712203
- https://github.com/langgenius/dify/pull/31392
- https://github.com/langgenius/dify/pull/31417
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-63387",
"cveTags": [
{
"tags": [
"disputed"
],
"sourceIdentifier": "cve@mitre.org"
}
],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-63387",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-19T17:32:01.989880Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2025-12-18T19:16:33.157",
"references": [
{
"url": "https://gist.github.com/Cristliu/cddc0cbbf354de51106ab63a11be94af",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://gist.github.com/Cristliu/dfc5f3a31dc6d7fff2754867e5c649a5",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/langgenius/dify/discussions",
"tags": [
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/langgenius/dify/issues/31368#issuecomment-3783712203",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/langgenius/dify/pull/31392",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/langgenius/dify/pull/31417",
"source": "cve@mitre.org"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed."
},
{
"lang": "es",
"value": "Dify v1.9.1 es vulnerable a Permisos Inseguros. Un atacante no autenticado puede enviar directamente solicitudes HTTP GET al endpoint /console/api/system-features sin ninguna credencial de autenticación o tokens de sesión. El endpoint no implementa controles de autorización adecuados, permitiendo el acceso anónimo a datos sensibles de configuración del sistema. NOTA: El mantenedor afirma que el endpoint no está autenticado por diseño y sirve como un mecanismo de arranque requerido para la inicialización del panel de control. También afirman que la descripción clasifica de forma imprecisa los datos devueltos como configuración sensible del sistema, afirmando que los datos no son sensibles y son requeridos para la renderización del lado del cliente. No se exponen PII, credenciales o secretos."
}
],
"lastModified": "2026-10-05T18:10:00.200",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "ABF9FC69-C390-446E-830C-5F8B0A0488F2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}