Medium severity5.4NVD Advisory· Published Jul 7, 2025· Updated Jun 17, 2026
CVE-2025-3467
CVE-2025-3467
Description
An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacker to obtain the administrator's token by sending a payload in the published chat. When the administrator views the conversation content through the monitoring/log function using Firefox, the XSS vulnerability is triggered, potentially exposing sensitive token information to the attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:*range: <1.1.3
- (no CPE)range: <1.1.3
- langgenius/langgenius/difyv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/langgenius/dify/commit/72deb3bed0b0d5d98d7cf44b525cc44bb278f6a7nvdPatch
- huntr.com/bounties/21723441-7b55-425c-abc4-b1331a713591nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.