CVE-2025-56157
CRITICALLanggenius Dify < 1.5.1 - Hard-coded Credentials
Title source: ruleDescription
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
References (8)
Scores
CVSS v3
9.8
EPSS
0.0004
EPSS Percentile
13.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-798
Status
published
Affected Products (1)
langgenius/dify
< 1.5.1
Timeline
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026