---
id: CVE-2025-11750
title: >-
  In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the
  existence of user accounts by returning different error messages for
  non-existent and existing accounts
summary: >-
  In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the
  existence of user accounts by returning different error messages for
  non-existent and existing accounts. Specifically, when a login or registration
  attempt is…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-544
vendor: langgenius
product: dify
affected:
  - dify = 1.6.0
published: '2025-10-22'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11750'
references:
  - url: 'https://huntr.com/bounties/e7359f9f-c004-4304-9de9-753622d370a1'
    label: security@huntr.dev
  - url: 'https://huntr.com/bounties/e7359f9f-c004-4304-9de9-753622d370a1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.007
epssPercentile: 0.517
exploits:
  nuclei:
    - CVE-2025-11750
  checkedAt: '2026-10-09T10:30:44.221Z'
exploitAvailable: true
ingestedAt: '2026-10-08T11:31:27.491Z'
---

## Overview

In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system responds with a message such as "account not found." Conversely, when the username or email exists but the password is incorrect, a different error message is returned. This discrepancy allows an attacker to enumerate valid user accounts by analyzing the error responses, potentially facilitating targeted social engineering, brute force, or credential stuffing attacks.

## Affected

- `dify = 1.6.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
