CVE-2025-63386

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration is intentional to support bootstrap.
Configurations

Configuration 1 (hide)

cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:*

History

11 Feb 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/langgenius/dify/pull/32224 -

11 Feb 2026, 11:16

Type Values Removed Values Added
Summary (en) A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. (en) A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration is intentional to support bootstrap.

22 Jan 2026, 18:16

Type Values Removed Values Added
References
  • () https://gist.github.com/Cristliu/8ad993126be05c9210c71cc7d49fa112 -

30 Dec 2025, 20:02

Type Values Removed Values Added
References () https://gist.github.com/Cristliu/1610daac87c711ac3e0250c58f5cc4f9 - () https://gist.github.com/Cristliu/1610daac87c711ac3e0250c58f5cc4f9 - Third Party Advisory
References () https://github.com/langgenius/dify/discussions - () https://github.com/langgenius/dify/discussions - Issue Tracking
First Time Langgenius
Langgenius dify
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:*

19 Dec 2025, 22:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CWE CWE-346

18 Dec 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-18 16:15

Updated : 2026-02-11 15:16


NVD link : CVE-2025-63386

Mitre link : CVE-2025-63386

CVE.ORG link : CVE-2025-63386


JSON object : View

Products Affected

langgenius

  • dify
CWE
NVD-CWE-noinfo CWE-346

Origin Validation Error