In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset…
@huntr_ai·CWE-305·Published 2025-03-20