Known Vulnerabilities for Dify by LangGenius
Listed below are 3 of the newest known vulnerabilities associated with "Dify" by "LangGenius".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-61461 json | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to ex... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-42138 json | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any un... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-41950 json | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full co... | Not Provided | 2026-05-05 | 2026-07-14 |
| CVE-2026-41949 json | Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authen... | Not Provided | 2026-05-18 | 2026-06-22 |
| CVE-2026-41948 json | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests f... | Not Provided | 2026-05-18 | 2026-06-22 |
| CVE-2026-41947 json | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and e... | Not Provided | 2026-05-18 | 2026-06-22 |
| CVE-2026-18266 json | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensi... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2025-56157 json | Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included i... | Not Provided | 2025-12-18 | 2026-07-05 |