CVE-2025-3467: XSS Vulnerability in langgenius/dify
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator views the conversation content through the monitoring/log function using Firefox, the XSS vulnerability is triggered, potentially exposing sensitive token information to the attacker.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
langgenius/difyto a version that resolves this vulnerability.Fixed in 1.1.3 - Compensating control
As a mitigation for the XSS affecting Firefox, avoid using Firefox to view conversation content via the monitoring/log function until the affected langgenius/dify version (prior to 1.1.3) is upgraded.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3467?
CVE-2025-3467 is considered a critical XSS vulnerability due to its ability to expose the administrator's token.
How do I fix CVE-2025-3467?
To fix CVE-2025-3467, upgrade to Langgenius Dify version 1.1.3 or later.
Who is affected by CVE-2025-3467?
CVE-2025-3467 affects users of Langgenius Dify versions prior to 1.1.3, specifically those using Firefox browsers.
What type of attack is possible with CVE-2025-3467?
CVE-2025-3467 allows attackers to exploit reflected XSS to hijack an administrator's session.
When was CVE-2025-3467 disclosed?
The vulnerability CVE-2025-3467 was disclosed as part of an ongoing security review of Langgenius Dify.