Dify CORS Misconfiguration Vulnerability in System Features Endpoint

Vulnerability

A CORS misconfiguration vulnerability has been identified in Dify version 1.9.1, specifically within the '/console/api/system-features' endpoint. This vulnerability arises from an overly permissive CORS policy that allows arbitrary Origin headers and includes 'Access-Control-Allow-Credentials: true'. As a result, any external domain can make authenticated cross-origin requests to the endpoint.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive system configuration information by allowing external domains to make authenticated requests to the vulnerable endpoint.

Added: Dec 18, 2025, 5:14 PM
Updated: Dec 18, 2025, 5:14 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
0.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.