A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration is intentional to support bootstrap.
References
Configurations
History
11 Feb 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 Feb 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implements an insecure CORS policy that reflects any Origin header and enables Access-Control-Allow-Credentials: true, permitting arbitrary external domains to make authenticated requests. NOTE: the Supplier disputes this because the endpoint configuration is intentional to support bootstrap. |
22 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Dec 2025, 20:02
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gist.github.com/Cristliu/1610daac87c711ac3e0250c58f5cc4f9 - Third Party Advisory | |
| References | () https://github.com/langgenius/dify/discussions - Issue Tracking | |
| First Time |
Langgenius
Langgenius dify |
|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:* |
19 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| CWE | CWE-346 |
18 Dec 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 16:15
Updated : 2026-02-11 15:16
NVD link : CVE-2025-63386
Mitre link : CVE-2025-63386
CVE.ORG link : CVE-2025-63386
JSON object : View
Products Affected
langgenius
- dify
CWE
