CVE-2026-26023

Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dify:dify:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:25

Type Values Removed Values Added
Summary
  • (es) Dify es una plataforma de desarrollo de aplicaciones LLM de código abierto. Antes de la versión 1.13.0, se ha encontrado una vulnerabilidad de cross-site scripting en el frontend de chat de la aplicación web al usar echarts. Las entradas de usuario o de LLM que contengan echarts con una carga útil de javascript específica se ejecutarán. Esta vulnerabilidad está corregida en la versión 1.13.0.

13 Feb 2026, 15:04

Type Values Removed Values Added
References () https://github.com/langgenius/dify/commit/378a1d7d08bd0ac5c75eaadc075a0f35211fcb8e - () https://github.com/langgenius/dify/commit/378a1d7d08bd0ac5c75eaadc075a0f35211fcb8e - Patch
References () https://github.com/langgenius/dify/releases/tag/1.13.0 - () https://github.com/langgenius/dify/releases/tag/1.13.0 - Product, Release Notes
References () https://github.com/langgenius/dify/security/advisories/GHSA-qqjx-5h5w-x5vj - () https://github.com/langgenius/dify/security/advisories/GHSA-qqjx-5h5w-x5vj - Exploit, Vendor Advisory
CPE cpe:2.3:a:dify:dify:*:*:*:*:*:*:*:*
First Time Dify
Dify dify
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

11 Feb 2026, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 22:15

Updated : 2026-06-17 10:25


NVD link : CVE-2026-26023

Mitre link : CVE-2026-26023

CVE.ORG link : CVE-2026-26023


JSON object : View

Products Affected

dify

  • dify
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')