CVE-2025-58747 describes a cross-site scripting (XSS) vulnerability in Dify versions through 1.9.1, specifically within its MCP OAuth component. An attacker can exploit this by setting up a malicious remote MCP server that provides a JavaScript URI in the authorization_url, which Dify then executes without proper validation. This allows for arbitrary JavaScript execution in the victim's Dify application context. The vulnerability carries a CVSS score of 6.1 (MEDIUM), indicating a network-based attack with low complexity requiring user interaction, potentially leading to limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.9.2CPE matchmatch criteria | cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.