Disclosure summary
In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system responds with a message such as "account not found." Conversely, when the username or email exists but the password is incorrect, a different error message is returned. This discrepancy allows an attacker to enumerate valid user accounts by analyzing the error responses, potentially facilitating targeted social engineering, brute force, or credential stuffing attacks.
Source-reported weakness categories
CWE-544
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-11750
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| langgenius | dify | 1.6.0 |
Original records & references
- NIST NVD record
- CVE Program record
- huntr.com — Exploit, Third Party Advisory
- huntr.com — Exploit, Third Party Advisory
PUBLISHED 2025-10-22T10:15:49-04:00
MODIFIED 2026-10-08T07:10:00-04:00
INGESTED 2026-10-08T12:35:06-04:00