CVE-2025-56157

CRITICAL

Langgenius Dify < 1.5.1 - Hard-coded Credentials

Title source: rule

Description

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-798
Status published

Affected Products (1)

langgenius/dify < 1.5.1

Timeline

Published Dec 18, 2025
Tracked Since Feb 18, 2026