CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-11750: dify 1.6.0; +1 more affected products

CVE-2025-11750. CVSS 3.1 base score 5.3 (MEDIUM, NVD). EPSS 0.007 (percentile 0.51595), scored 2026-10-06.

Affected technology

dify · 1.6.0
langgenius

langgenius/dify · unspecified through latest
langgenius

Description’s affected range: version 1.6.0

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An attacker can enumerate valid user accounts by analyzing the error responses, potentially facilitating targeted social engineering, brute force, or credential stuffing attacks. NVD’s CVSS 3.1 assessment (base score 5.3/10) rates confidentiality impact as low; integrity and availability impact as none.

Published

CWE
CWE-544
CCR priority
21.4 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N · NVD
EPSS
0.007 · percentile 0.517 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-11750.html