Home

Description

Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0.

PUBLISHED Reserved 2026-02-09 | Published 2026-02-11 | Updated 2026-02-12 | Assigner GitHub_M




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

< 1.13.0
affected

References

github.com/...s/dify/security/advisories/GHSA-qqjx-5h5w-x5vj

github.com/...ommit/378a1d7d08bd0ac5c75eaadc075a0f35211fcb8e

github.com/langgenius/dify/releases/tag/1.13.0

cve.org (CVE-2026-26023)

nvd.nist.gov (CVE-2026-26023)

Download JSON