CVE-2025-43854: DIFY vulnerable to Clickjacking Attack
DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
difyto a version that resolves this vulnerability.Fixed in 1.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43854?
CVE-2025-43854 is considered a moderate severity vulnerability due to its potential to exploit user trust through clickjacking.
How do I fix CVE-2025-43854?
To fix CVE-2025-43854, upgrade to DIFY version 1.3.0 or later, which addresses the clickjacking vulnerability.
What are the potential impacts of CVE-2025-43854?
The potential impacts of CVE-2025-43854 include unauthorized actions performed by users without their consent due to manipulation of webpage elements.
Who is affected by CVE-2025-43854?
CVE-2025-43854 affects users of DIFY prior to version 1.3.0, specifically in the default setup of the application.
What type of vulnerability is CVE-2025-43854?
CVE-2025-43854 is a clickjacking vulnerability that allows malicious actors to deceive users into interacting with content they cannot see.