CVE-2025-56157
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
http://dify.com, https://gist.github.com/Cristliu/216ddbadaf3258498c93d408683ecabd, https://gist.github.com/Cristliu/298f51cbc72c45d91632cd0d65aa8161, https://github.com/langgenius/dify/releases/tag/1.0.1, https://gist.github.com/Cristliu/216ddbadaf3258498c93d408683ecabd, https://github.com/langgenius/dify/issues/15285, https://github.com/langgenius/dify/pull/15286, https://github.com/langgenius/dify/pull/15286.diff, https://github.com/langgenius/dify, https://gist.github.com/Cristliu/216ddbadaf3258498c93d408683ecabd
