CVE-2025-11750Medium· 5.3▾ TwilightPoC availableIn langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
Nuclei ×1 (last check)
In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system responds with a message such as "account not found." Conversely, when the username or email exists but the password is incorrect, a different error message is returned. This discrepancy allows an attacker to enumerate valid user accounts by analyzing the error responses, potentially facilitating targeted social engineering, brute force, or credential stuffing attacks.
dify = 1.6.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105762High· 8.3Dify is an open-source LLM app development platform
CVE-2025-63387High· 7.5Dify v1.9.1 is vulnerable to Insecure Permissions
CVE-2026-105761High· 7.1Dify is an open-source LLM app development platform
CVE-2025-67732Medium· 6.5Dify is an open-source LLM app development platform
CVE-2025-3467Medium· 5.4An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers
CVE-2026-20321Medium· 6.5A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user