
AI Platform Dify Exposes Users to One-Click Account Takeover
Why This Matters Now: In December 2024, a critical vulnerability was discovered in Dify, an AI platform with over 10 million users. This vulnerability allows attackers to perform one-click account takeovers, posing significant risks to user data and security. Given the widespread adoption of Dify, this issue has become urgent, requiring immediate attention from developers and security teams. 馃毃 Breaking: Over 10 million users of Dify are at risk of one-click account takeover. Update your installations and rotate API keys immediately. 10M+Users Affected 24hrsTime to Act Understanding the Vulnerability The core issue lies in how Dify handles OAuth authentication. Specifically, the platform uses a default OAuth scope that grants excessive permissions, allowing attackers to escalate privileges and take over user accounts with minimal effort. ...


