ASR AI Security Radar

Back to incidents

AI security incident: CVE-2025-67732 (NVD)

Incident date: January 5, 2026 | Published: February 14, 2026

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reuse it. This can lead to unauthorized access to third-party services, potentially consuming limited quotas. Version 1.11.0 fixes the issue.

Impact

Severity HIGH. Confidence 50%. Source channel: NVD.

Recommended Response

Sources

Want alerts like this in real time?

Get notified with incident context, likely impact, and response guidance.

Get Notified

More incidents