Dify v1.9.1 contains an insecure permissions vulnerability caused by lack of authorization checks in /console/api/system-features endpoint, letting unauthenticated attackers access sensitive system configuration data.
id: CVE-2025-63387
info:
name: Dify v1.9.1 - Broken Access Control
author: DhiyaneshDK
severi
...