Description
Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
References
github.com/...s/dify/security/advisories/GHSA-qqjx-5h5w-x5vj
github.com/...ommit/378a1d7d08bd0ac5c75eaadc075a0f35211fcb8e
github.com/langgenius/dify/releases/tag/1.13.0