Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

dify — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in dify, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses and vulnerabilities affecting Dify, an open-source large language model application development platform. It aggregates data regarding various vulnerability classifications, including but not limited to cross-site scripting, broken access control, and insecure direct object references that may impact the integrity or confidentiality of the platform. The collected information encompasses advisory records, patch releases, and impact assessments spanning from the product's initial public availability to the present day, ensuring a comprehensive historical view of its security posture. By reviewing this aggregated data, users can effectively track vendor advisories to stay informed about critical updates and mitigation strategies. It also allows security professionals to understand specific weakness classes within the context of generative AI tooling, facilitating better risk assessment for deployments. Furthermore, the page enables users to look up the vulnerability history of Dify, providing insights into past incidents, resolution timelines, and the evolution of security practices within the development lifecycle. This resource serves as a centralized reference for developers, DevOps engineers, and security analysts who need to evaluate the trustworthiness of the platform or conduct audits. The content is compiled from official vendor announcements, independent security research, and community reports to ensure accuracy and completeness. This structured overview supports informed decision-making regarding the adoption and maintenance of Dify in enterprise or personal projects.

Vendor: langgenius

CVE ID Title CVSS Severity Published
CVE-2026-18632 langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine CWE-1336 6.3 Medium 2026-08-03
CVE-2026-18266 Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability CWE-601 - - 2026-07-29
CVE-2026-61461 Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text CWE-89 8.8 High 2026-07-10
CVE-2026-41949 Dify < 1.14.2 Authorization Bypass via File Preview Endpoint CWE-639 5.9 Medium 2026-05-18
CVE-2026-41948 Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access CWE-23 9.4 Critical 2026-05-18
CVE-2026-41947 Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints CWE-639 9.1 Critical 2026-05-18
CVE-2026-41950 Dify < 1.14.0 Authorization Bypass via File UUID CWE-639 6.5 Medium 2026-05-05
CVE-2026-42138 Dify Vulnerable to Stored XSS via SVG-file upload CWE-79 6.1 - 2026-05-04
CVE-2026-34082 Dify has IDOR in deleting someone else's chat conversation CWE-863 4.3AI Medium AI 2026-04-20
CVE-2026-6619 langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting CWE-79 3.5 Low 2026-04-20
CVE-2026-6618 langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery CWE-918 6.3 Medium 2026-04-20
CVE-2026-6617 langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgery CWE-918 6.3 Medium 2026-04-20
CVE-2026-21866 Dify - Stored XSS in chat CWE-79 5.4AI Medium AI 2026-03-03
CVE-2026-28288 Dify has a user enumeration issue CWE-204 5.3 - 2026-02-27
CVE-2026-26023 Client‑side DOM XSS in the web chat app of Dify when using echarts CWE-79 6.1AI Medium AI 2026-02-11
CVE-2025-67732 Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint CWE-200 5.4 - 2026-01-05
CVE-2025-58747 Dify MCP OAuth Flow Vulnerable to XSS CWE-79 6.1AI Medium AI 2025-10-17
CVE-2025-59422 Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Others CWE-284 4.3AI Medium AI 2025-09-25
CVE-2025-49149 Dify has XSS vulnerability CWE-79 6.1AI Medium AI 2025-06-17
CVE-2025-43854 DIFY vulnerable to Clickjacking Attack CWE-1021 6.1AI Medium AI 2025-04-28
CVE-2025-43862 Dify Allows Unauthorized Access and Modification of APP Orchestration CWE-284 7.6 High 2025-04-25
CVE-2025-32796 Dify Allows Unauthorized APP Enable/Disable via API CWE-284 6.5 Medium 2025-04-18
CVE-2025-32795 Dify Allows Insecure User Role Access Control for APP Editing CWE-284 6.5 Medium 2025-04-18
CVE-2025-32790 Dify Allows Insecure User Role Access Control for APP DSL Exporting CWE-284 6.3 Medium 2025-04-18

All 24 known CVE vulnerabilities affecting dify with full Chinese analysis, references, and POCs where available.