CVE-2025-67732: Dify Patch Fixes High-Severity Plaintext API Key Exposure
ID: bcc9fc36-515e-5456-9ae3-64d66f472bdd
STIX ID: report--bcc9fc36-515e-5456-9ae3-64d66f472bdd
Feed Name: securityonline.info
Threat Score
A high-severity vulnerability (CVE-2025-67732, CVSS 8.4) in Dify causes the backend endpoint /console/api/workspaces/current/model-providers to return full configuration objects that include plaintext API keys, allowing non-administrator users to harvest credentials via standard browser developer tools; the issue affects Dify ≤ 1.10.1-fix.1 and is fixed in 1.11.0, with recommended immediate upgrades to mitigate financial and operational impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
