CVE-2025-67732: Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited quotas. Version 1.11.0 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67732?
CVE-2025-67732 is considered a medium severity vulnerability due to the potential for unauthorized access to third-party services.
How do I fix CVE-2025-67732?
To fix CVE-2025-67732, update your Dify platform to version 1.11.0 or later where the API key exposure issue has been resolved.
What are the risks associated with CVE-2025-67732?
The risks associated with CVE-2025-67732 include unauthorized access to third-party services and the potential for quota consumption.
Who is affected by CVE-2025-67732?
Any users of Dify prior to version 1.11.0 are affected by CVE-2025-67732 due to the exposed API key.
How can the API key exposure in CVE-2025-67732 be exploited?
The API key exposure in CVE-2025-67732 can be exploited by non-administrator users who can view and reuse the key to access restricted functionalities.