2025-12-18 · 2 min · BitNinja Team

CVE-2025-63388: Addressing Dify CORS Misconfiguration

In December 2025, a significant Cross-Origin Resource Sharing (CORS) misconfiguration was discovered in Dify version 1.9.1. This vulnerability exposes the /console/api/system-features endpoint, allowing any external domain to make authenticated cross-origin requests. The impli...

CVE-2025-63388: Addressing Dify CORS Misconfiguration

← All postsPricingSolutions