Known Vulnerabilities for Dify by LangGenius
Listed below are 3 of the newest known vulnerabilities associated with "Dify" by "LangGenius".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61461 json | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to ex... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-42138 json | Not Provided | 2026-05-04 | 2026-05-11 | |
| CVE-2026-41950 json | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full co... | Not Provided | 2026-05-05 | 2026-07-14 |
| CVE-2026-41949 json | Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authen... | Not Provided | 2026-05-18 | 2026-06-22 |
| CVE-2026-41948 json | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests f... | Not Provided | 2026-05-18 | 2026-06-22 |
| CVE-2026-41947 json | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and e... | Not Provided | 2026-05-18 | 2026-06-22 |
| CVE-2026-18632 json | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the f... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18266 json | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensi... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2025-56157 json | Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included i... | Not Provided | 2025-12-18 | 2026-07-05 |