Dify

Langgenius · 44 CVEs

CVE-2026-105762
HIGH

Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint

Oct 5, 2026

CVE-2026-105761
HIGH

Dify: IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers

Oct 5, 2026

CVE-2026-85022
MEDIUM

langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting

Sep 3, 2026

CVE-2026-85021
MEDIUM

langgenius dify Splash Layout splash.tsx router.replace cross site scripting

Sep 3, 2026

CVE-2026-18632
MEDIUM

langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine

Aug 3, 2026

CVE-2026-18266
MEDIUM

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability

Jul 29, 2026

CVE-2026-61461
HIGH

Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text

Jul 10, 2026

CVE-2026-41949
HIGH

Dify < 1.14.2 Authorization Bypass via File Preview Endpoint

May 18, 2026

CVE-2026-41948
CRITICAL

Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access

May 18, 2026

CVE-2026-41947
CRITICAL

Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints

May 18, 2026

CVE-2026-41950
MEDIUM

Dify < 1.14.0 Authorization Bypass via File UUID

May 5, 2026

CVE-2026-42138
MEDIUM

Dify Vulnerable to Stored XSS via SVG-file upload

May 4, 2026

CVE-2026-34082
MEDIUM

Dify has IDOR in deleting someone else's chat conversation

Apr 20, 2026

CVE-2026-6619
MEDIUM

langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting

Apr 20, 2026

CVE-2026-6618
MEDIUM

langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery

Apr 20, 2026

CVE-2026-6617
MEDIUM

langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side reques…

Apr 20, 2026

CVE-2026-21866
MEDIUM

Dify - Stored XSS in chat

Mar 3, 2026

CVE-2026-28288
MEDIUM

Dify has a user enumeration issue

Feb 27, 2026

CVE-2026-26023
MEDIUM

Client‑side DOM XSS in the web chat app of Dify when using echarts

Feb 11, 2026

CVE-2025-67732
HIGH

Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint

Jan 5, 2026

CVE-2025-63387
HIGH

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to t…

Dec 18, 2025

CVE-2025-63388
CRITICAL

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-…

Dec 18, 2025

CVE-2025-63386
CRITICAL

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup e…

Dec 18, 2025

CVE-2025-56157
CRITICAL

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file incl…

Dec 18, 2025

CVE-2025-11750
MEDIUM

User Enumeration via Distinct Error Messages in langgenius/dify-web

Oct 22, 2025

Showing 1 to 25 of 44 CVEs