---
id: CVE-2026-105761
title: Dify is an open-source LLM app development platform
summary: >-
  Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT
  /console/api/apps/&lt;app_id&gt;/server endpoint in
  api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to
  retrieve an AppMCPServer by …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-639
vendor: langgenius
product: dify
affected:
  - dify < 1.16.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T23:17:03.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105761'
references:
  - url: >-
      https://github.com/langgenius/dify/commit/62cb5b586504b730731e28e743c038b72950058e
    label: security-advisories@github.com
  - url: 'https://github.com/langgenius/dify/pull/38177'
    label: security-advisories@github.com
  - url: 'https://github.com/langgenius/dify/releases/tag/1.16.0'
    label: security-advisories@github.com
  - url: 'https://github.com/langgenius/dify/security/advisories/GHSA-ccrj-frp2-c945'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T23:36:21.158Z'
---

## Overview

Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;app_id&gt;/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore change another application's MCP server status and parameters, potentially redirecting data or disabling the service. This issue is fixed in version 1.16.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
