Langgenius

Dify

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 05.10.2026 23:04:58
  • Zuletzt bearbeitet 06.10.2026 16:08:43

Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrie...

  • EPSS 0.25%
  • Veröffentlicht 05.10.2026 23:03:44
  • Zuletzt bearbeitet 06.10.2026 16:08:43

Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-su...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 03.09.2026 00:45:14
  • Zuletzt bearbeitet 03.09.2026 17:25:25

A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the component WebApp Sign-In. Such manipu...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 03.09.2026 00:30:10
  • Zuletzt bearbeitet 03.09.2026 17:25:25

A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.08.2026 19:30:08
  • Zuletzt bearbeitet 12.08.2026 21:00:37

A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in i...

  • EPSS 0.24%
  • Veröffentlicht 29.07.2026 19:05:20
  • Zuletzt bearbeitet 30.07.2026 14:19:24

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the ta...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.07.2026 18:10:35
  • Zuletzt bearbeitet 08.10.2026 16:17:25

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or paramete...

Medienbericht Exploit
  • EPSS 0.44%
  • Veröffentlicht 18.05.2026 13:52:03
  • Zuletzt bearbeitet 22.06.2026 18:16:37

Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's ...

Medienbericht Exploit
  • EPSS 6.99%
  • Veröffentlicht 18.05.2026 13:50:21
  • Zuletzt bearbeitet 22.06.2026 18:16:37

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse ou...

Medienbericht Exploit
  • EPSS 5.97%
  • Veröffentlicht 18.05.2026 13:48:03
  • Zuletzt bearbeitet 22.06.2026 18:16:36

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership. Attackers can exploit missing tenant ownership...