EXECUTIVE SUMMARY:
CVE-2025-67732 is a high-severity (CVSS 8.4) vulnerability in the open-source Dify LLM application platform that affects all versions up to 1.10.1-fix.1, where a backend API endpoint inadvertently returns sensitive API keys in plaintext to the frontend, exposing them to any non-administrator user who can access the interface, and thus allowing those users to view and potentially reuse credentials for integrated third-party services without proper authorization, which could lead to unauthorized access and quota consumption on those services.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
CVE-2025-67732 is a high-severity (CVSS 8.4) vulnerability in the open-source Dify LLM application platform that affects all versions up to 1.10.1-fix.1, where a backend API endpoint inadvertently returns sensitive API keys in plaintext to the frontend, exposing them to any non-administrator user who can access the interface, and thus allowing those users to view and potentially reuse credentials for integrated third-party services without proper authorization, which could lead to unauthorized access and quota consumption on those services.[emaillocker id="1283"]
RECOMMENDATION:
We strongly recommend you update Dify to version 1.11.0.
REFERENCES:
The following reports contain further technical details:
[/emaillocker]