PT-2026-22832 · Dify · Dify

Cataliniovita-Snyk

·

Published

2026-03-03

·

Updated

2026-03-04

·

CVE-2026-21866

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dify versions prior to 1.11.2
Description Dify, an open-source LLM app development platform, contains a stored cross-site scripting (XSS) issue when rendering Mermaid diagrams within chats. The issue stems from Dify’s default Mermaid configuration utilizing a securityLevel of loose, which permits the execution of potentially unsafe content.
Recommendations Update to version 1.11.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-21866
GHSA-QPV6-75C2-75H4

Affected Products

Dify