LangGenius Dify
cpe:2.3:a:langgenius:dify:*:*:*:*:node.js:*:*
- 1.9.1
A CORS misconfiguration vulnerability has been identified in Dify version 1.9.1, specifically within the '/console/api/system-features' endpoint. This vulnerability arises from an overly permissive CORS policy that allows arbitrary Origin headers and includes 'Access-Control-Allow-Credentials: true'. As a result, any external domain can make authenticated cross-origin requests to the endpoint.
Exploitation of this vulnerability could lead to unauthorized access to sensitive system configuration information by allowing external domains to make authenticated requests to the vulnerable endpoint.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.