Security: langgenius/dify
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP ServersGHSA-ccrj-frp2-c945 published
Aug 19, 2026 by laipz8200High -
Cross-Tenant File Preview via Unscoped Console `file_id`GHSA-9c9q-5rj5-mjj2 published
Jul 15, 2026 by laipz8200High -
Cross-Tenant External API Usage EnumerationGHSA-fj5w-7rc8-3f3f published
Jul 15, 2026 by laipz8200Moderate -
Cross-Tenant External API Detail DisclosureGHSA-5vmp-5q9h-hmr7 published
Jul 15, 2026 by laipz8200High -
Client‑side DOM XSS in the web chat app of Dify when using echartsGHSA-qqjx-5h5w-x5vj published
Feb 11, 2026 by 41tairHigh -
Dify - Stored XSS in chatGHSA-qpv6-75c2-75h4 published
Mar 3, 2026 by laipz8200Moderate -
Plaintext API Key Exposure via Model Provider Configuration EndpointGHSA-phpv-94hg-fv9g published
Jan 4, 2026 by laipz8200High -
Stored XSS via SVG-file uploadGHSA-cg94-8v83-7hjj published
Apr 20, 2026 by laipz8200Moderate -
User enumerationGHSA-9qpf-wcv3-w3qx published
Feb 27, 2026 by laipz8200Low -
IDOR in deleting someone else's chat conversationGHSA-fxq3-hh7x-c63p published
Apr 20, 2026 by laipz8200Moderate