dify-client
A package for interacting with the Dify Service-API
Activity
- Latest release
- 2y ago
- Total releases
- 7
- Cadence
- ~daily
- Last 12 months
- 0
Details
- License
- MIT
- First release
- May 14, 2023
| Version | Released | |
|---|---|---|
0.1.10
patch
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev | ||
0.1.8
patch
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev | ||
0.1.7
patch
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev | ||
0.1.6
patch
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev | ||
0.1.5
patch
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev | ||
0.1.4
patch
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev | ||
0.1.3
initial
1 CVE
CVE-2025-63387
PYSEC-2025-103
Dec 18, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-features endpoint without any authentication credentials or session tokens. The endpoint fails to implement proper authorization checks, allowing anonymous access to sensitive system configuration data. NOTE: The maintainer states that the endpoint is unauthenticated by design and serves as a bootstrap mechanism required for the dashboard initialization. They also state that the description inaccurately classifies the returned data as sensitive system configuration, stating that the data is non-sensitive and required for client-side rendering. No PII, credentials, or secrets are exposed. Affected versions
0.1.10
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
References
Updated May 21, 2026 · Source: OSV.dev |