CVE-2025-56157
CRITICALLanggenius Dify < 1.5.1 - Hard-coded Credentials
Title source: ruleDescription
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
References (8)
Scores
CVSS v3
9.8
EPSS
0.0006
EPSS Percentile
18.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-798
Status
published
Products (1)
langgenius/dify
< 1.5.1
Published
Dec 18, 2025
Tracked Since
Feb 18, 2026