---
id: CVE-2025-3467
title: >-
  An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3,
  specifically affecting Firefox browsers
summary: >-
  An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3,
  specifically affecting Firefox browsers. This vulnerability allows an attacker
  to obtain the administrator's token by sending a payload in the published
  chat. When t…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: langgenius
product: dify
affected:
  - dify < 1.1.3
patched:
  - dify 1.1.3
published: '2025-07-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:10:01.007'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-3467'
references:
  - url: >-
      https://github.com/langgenius/dify/commit/72deb3bed0b0d5d98d7cf44b525cc44bb278f6a7
    label: security@huntr.dev
  - url: 'https://huntr.com/bounties/21723441-7b55-425c-abc4-b1331a713591'
    label: security@huntr.dev
tags:
  - nvd
epss: 0.0037
epssPercentile: 0.28542
ingestedAt: '2026-09-30T19:21:07.237Z'
---

## Overview

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator views the conversation content through the monitoring/log function using Firefox, the XSS vulnerability is triggered, potentially exposing sensitive token information to the attacker.

## Affected

- `dify < 1.1.3`

## Remediation

Upgrade past the affected range:

- `dify 1.1.3`
