CVE-2025-59422 | langgenius dify 1.8.1 Chat Message chat-messages conversation_id access control

SecurityVulns

A vulnerability classified as critical was found in langgenius dify 1.8.1. Impacted is an unknown function of the file /console/api/apps/chat-messages of the component Chat Message Handler. The manipulation of the argument conversation_id results in improper access controls.

This vulnerability is identified as CVE-2025-59422. The attack can be executed remotely. There is not any exploit available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More