Dify is a modestly represented, widely deployed open-source platform for building and managing large language model applications, where its narrow product footprint belies prominence in the AI/LLM development landscape. Vulnerabilities affecting the platform skew toward serious outcomes, frequently acquire public exploit code, and cluster around web application and integration weaknesses including authorization bypasses, cross-site scripting, server-side request forgery, and improper access control—exposures typical of user-facing application frameworks handling diverse input sources and external service integration. Defenders deploying or embedding this platform should track security updates closely, particularly for authorization and injection-related flaws; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dify over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-61461HIGH Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search par | Jul 10, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-41948CRITICAL Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by ex | May 18, 2026 | 9.4 | 39 | NO | NO |
CVE-2026-41947CRITICAL Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardle | May 18, 2026 | 9.1 | 37 | NO | NO |
CVE-2026-41949HIGH Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uplo | May 18, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-56520MEDIUM Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CV | Sep 30, 2025 | 5.3 | 31 | NO | YES |
CVE-2026-28288MEDIUM Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate ema | Feb 27, 2026 | 5.3 | 30 | NO | YES |
CVE-2025-67732MEDIUM Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reus | Jan 5, 2026 | 6.5 | 25 | NO | NO |
CVE-2025-0185HIGH A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the functio | Mar 20, 2025 | 8.8 | 24 | NO | NO |
CVE-2026-21866MEDIUM Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dif | Mar 3, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-26023MEDIUM Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. U | Feb 11, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dify.
Media articles that mention a CVE ID that affects a product developed by Dify — matched by CVE ID, not by vendor name.