CVE-2025-56157

CRITICAL

Langgenius Dify < 1.5.1 - Hard-coded Credentials

Title source: rule
STIX 2.1

Description

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

Scores

CVSS v3 9.8
EPSS 0.0006
EPSS Percentile 18.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
langgenius/dify < 1.5.1
Published Dec 18, 2025
Tracked Since Feb 18, 2026