Threat Advisory

High-Severity Dify Vulnerability Exposes Plaintext API Keys

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2025-67732 is a high-severity (CVSS 8.4) vulnerability in the open-source Dify LLM application platform that affects all versions up to 1.10.1-fix.1, where a backend API endpoint inadvertently returns sensitive API keys in plaintext to the frontend, exposing them to any non-administrator user who can access the interface, and thus allowing those users to view and potentially reuse credentials for integrated third-party services without proper authorization, which could lead to unauthorized access and quota consumption on those services.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2025-67732 is a high-severity (CVSS 8.4) vulnerability in the open-source Dify LLM application platform that affects all versions up to 1.10.1-fix.1, where a backend API endpoint inadvertently returns sensitive API keys in plaintext to the frontend, exposing them to any non-administrator user who can access the interface, and thus allowing those users to view and potentially reuse credentials for integrated third-party services without proper authorization, which could lead to unauthorized access and quota consumption on those services.[emaillocker id="1283"]

RECOMMENDATION:

We strongly recommend you update Dify to version 1.11.0.

REFERENCES:

The following reports contain further technical details:

https://securityonline.info/cve-2025-67732-dify-patch-fixes-high-severity-plaintext-api-key-exposure/

[/emaillocker]
crossmenu