Critical
Low
Medium
CVE-2025-58747
Overview
Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects to an attacker-controlled remote MCP server. The vulnerability exists in the OAuth flow implementation where the authorization_url pro...
Critical
Low
Medium
No items found.