CVE-2025-56157
Dify Default Credentials Vulnerability
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
Dify versions up to 1.5.1 are affected by a vulnerability where default PostgreSQL credentials are included in the source code. If reachable, this could allow unauthorized access to data and system control. The vendor notes that the database port is not exposed by default in later versions, but the presence of hardcode