Description

Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/<APP_ID>chat-messages?conversation_id=<CONVERSATION_ID>&limit=10 endpoint allows users in the same workspace to read chat messages of other users. A regular user is able to read the query data and the filename of the admins and probably other users chats, if they know the conversation_id. This impacts the confidentiality of chats. This issue has been patched in version 1.9.0.

INFO

Published Date :

2025-09-25T13:19:11.385Z

Last Modified :

2025-09-25T15:14:52.506Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59422 vulnerability.

Vendors Products
Langgenius
  • Dify
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-59422.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact