Known Vulnerabilities for products from Langgenius
Listed below are 5 of the newest known vulnerabilities associated with the vendor "Langgenius".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-85022 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-85021 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-42138 json | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any un... | Not Provided | 2026-05-04 | 2026-05-11 |
| CVE-2026-41950 json | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full co... | Not Provided | 2026-05-05 | 2026-07-24 |
| CVE-2026-18632 json | Not Provided | 2026-08-03 | 2026-08-03 | |
| CVE-2025-63387 json | Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /co... | Not Provided | 2025-12-18 | 2026-10-05 |
| CVE-2025-56157 json | Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included i... | Not Provided | 2025-12-18 | 2026-07-05 |
| CVE-2025-3467 json | An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnera... | Not Provided | 2025-07-07 | 2026-09-30 |