Known Vulnerabilities for Dify by Langgenius
Listed below are 5 of the newest known vulnerabilities associated with "Dify" by "Langgenius".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105762 json | Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/co... | Not Provided | 2026-10-06 | 2026-10-05 |
| CVE-2026-105761 json | Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoin... | Not Provided | 2026-10-05 | 2026-10-05 |
| CVE-2026-85022 json | A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of th... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-85021 json | A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareL... | Not Provided | 2026-09-03 | 2026-09-03 |
| CVE-2026-61461 json | Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to ex... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-42138 json | Not Provided | 2026-05-04 | 2026-05-11 | |
| CVE-2026-41950 json | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full co... | Not Provided | 2026-05-05 | 2026-07-14 |
| CVE-2026-18632 json | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the f... | Not Provided | 2026-08-03 | 2026-08-03 |
| CVE-2026-18266 json | Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensi... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2025-63387 json | Not Provided | 2025-12-18 | 2026-10-05 |