Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-63388

32
FAUCET Score

CVE-2025-63388 describes a critical Cross-Origin Resource Sharing (CORS) misconfiguration in Dify v1.9.1, specifically affecting the /console/api/system-features endpoint. This vulnerability allows any external domain to make authenticated cross-origin requests due to an overly permissive CORS policy that reflects arbitrary Origin headers and sets Access-Control-Allow-Credentials: true. With a CVSS score of 9.1 (CRITICAL), this network-exploitable vulnerability requires no user interaction and could lead to high confidentiality and integrity impacts. While the vendor disputes the severity, arguing no additional access is gained, there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules available. However, the vulnerability has garnered significant community discussion, with 10 mentions, indicating considerable attention.

Impacted Technologies

VendorProductVersion(s)CPE
1.9.1CPE matchmatch criteria
cpe:2.3:a:langgenius:dify:1.9.1:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
11.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 0th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

gist.github.com / Cristliu/5ded6d03e41d7d66ecb1b568bae3ff6c
Third Party Advisory
gist.github.com / Cristliu/c2bc7d05abd89db8eb542a453a528d77
github.com / langgenius/dify/discussions
Issue Tracking