Known Vulnerabilities for Dify by Langgenius
Listed below are 2 of the newest known vulnerabilities associated with "Dify" by "Langgenius".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42138 json | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any un... | Not Provided | 2026-05-04 | 2026-05-04 |
| CVE-2026-41950 json | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full co... | Not Provided | 2026-05-05 | 2026-05-06 |
| CVE-2026-41949 json | Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authen... | Not Provided | 2026-05-18 | 2026-05-26 |
| CVE-2026-41948 json | Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests f... | Not Provided | 2026-05-18 | 2026-05-26 |
| CVE-2026-41947 json | Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and e... | Not Provided | 2026-05-18 | 2026-05-26 |
| CVE-2026-34082 json | Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/ |
Not Provided | 2026-04-20 | 2026-04-21 |
| CVE-2026-6619 json | A vulnerability has been found in langgenius dify up to 1.13.3. Impacted is the function openInNewTab of the file web/app/com... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-6618 json | A flaw has been found in langgenius dify up to 1.13.3. This issue affects the function parse_openai_plugin_json_to_tool_bundl... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-6617 json | A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_re... | Not Provided | 2026-04-20 | 2026-04-20 |