A high-severity vulnerability, tracked as CVE-2025-67732, was discovered in the open-source LLM app development platform Dify. The flaw allowed API keys to be exposed in plaintext through the model provider configuration endpoint, making them accessible to non-administrator users via the frontend. This exposure could enable unauthorized individuals to view and reuse the API keys, potentially granting them access to third-party services and consuming limited quotas. The issue was addressed and fixed in Dify version 1.11.0, mitigating the risk of unauthorized access.
Security advisories highlighted the remote exploitability of this vulnerability, emphasizing the risk of API key leakage and subsequent misuse. The vulnerability was assigned a CVSS 4.0 score of 8.4, reflecting its high severity. Organizations using Dify are urged to update to version 1.11.0 or later to prevent exploitation and protect sensitive API credentials from exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-67732 was published as a high-severity vulnerability affecting Dify versions prior to 1.11.0. The disclosure described remote exploitation risks from plaintext API key exposure and potential unauthorized use of third-party services.
Dify fixed a high-severity flaw that exposed model provider API keys in plaintext to non-administrator users via the Model Provider Configuration endpoint. The issue was resolved in version 1.11.0, and users were advised to update and rotate any exposed keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.