
AI Platform Dify Exposes Users to One-Click Account Takeover
Why This Matters Now: In December 2024, a critical vulnerability was discovered in Dify, an AI platform with over 10 million users. This vulnerability allows attackers to perform one-click account takeovers, posing significant risks to user data and security. Given the widespread adoption of Dify, this issue has become urgent, requiring immediate attention from developers and security teams. 🚨 Breaking: Over 10 million users of Dify are at risk of one-click account takeover. Update your installations and rotate API keys immediately. 10M+Users Affected 24hrsTime to Act Understanding the Vulnerability The core issue lies in how Dify handles OAuth authentication. Specifically, the platform uses a default OAuth scope that grants excessive permissions, allowing attackers to escalate privileges and take over user accounts with minimal effort. ...