Dify · Dify · CVE-2026-42138
**Name of the Vulnerable Software and Affected Versions**
Dify versions prior to 1.13.1
**Description**
An issue exists in this open-source LLM app development platform where users can upload SVG files containing Cross-Site Scripting (XSS), which is a technique that allows attackers to execute malicious scripts in the victim's browser. This can be achieved through the unauthenticated endpoint "POST /api/files/upload" or the authenticated endpoint "POST /v1/files/upload".
**Recommendations**
Update to version 1.13.1.