Aller au contenu principal
HIGH

CVE-2025-63387

CVSS v3

7.5

HIGH

Score EPSS

29.9 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed.

Détails techniques

Publiée le
2025-12-18

Questions fréquentes

Qu’est-ce que CVE-2025-63387 ?

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed.

CVE-2025-63387 est-elle activement exploitée ?

Aucune exploitation active de CVE-2025-63387 n’est confirmée. Son score EPSS était de 29.9 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2025-63387 ?

CVE-2025-63387 a un score de base CVSS v3 de 7.5 (gravité HIGH).

CVE-2025-63387 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite