What happened
The PUT /console/api/apps/<app_id>/server endpoint retrieves an AppMCPServer by client-supplied server ID without verifying tenant/application ownership. An authenticated workspace member can change another application's MCP server status and parameters — redirecting data flows or disabling the service. Fixed in 1.16.0.
Why it matters
MCP server config is the agent data path in Dify apps; cross-app tampering lets a workspace member redirect another app's agent tool traffic or knock it offline.
Attack vector
Authenticated PUT to the app MCP server endpoint with a server ID belonging to another application/tenant.
Affected systems
Dify (langgenius/dify) < 1.16.0
Mitigation
Upgrade to Dify 1.16.0.