PT-2026-22832 · Dify · Dify

Cataliniovita-Snyk

·

Publicado

2026-03-03

·

Atualizado

2026-03-04

·

CVE-2026-21866

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dify versions prior to 1.11.2
Description Dify, an open-source LLM app development platform, contains a stored cross-site scripting (XSS) issue when rendering Mermaid diagrams within chats. The issue stems from Dify’s default Mermaid configuration utilizing a securityLevel of loose, which permits the execution of potentially unsafe content.
Recommendations Update to version 1.11.2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21866
GHSA-QPV6-75C2-75H4

Produtos afetados

Dify