Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langgenius
Langgenius dify |
|
| Vendors & Products |
Langgenius
Langgenius dify |
Mon, 05 Oct 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore change another application's MCP server status and parameters, potentially redirecting data or disabling the service. This issue is fixed in version 1.16.0. | |
| Title | Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T23:03:44.949Z
Reserved: 2026-10-05T19:11:07.948Z
Link: CVE-2026-105761
No data.
Status : Received
Published: 2026-10-05T23:17:03.050
Modified: 2026-10-05T23:17:03.050
Link: CVE-2026-105761
No data.
OpenCVE Enrichment
Updated: 2026-10-06T00:30:18Z