Security Flaw in langgenius Dify Affects Template Engine Handler
CVE-2026-18632
Key Information:
- Vendor
Langgenius
- Status
- Vendor
- CVE Published:
- 3 August 2026
Badges
What is CVE-2026-18632?
A notable vulnerability has been identified in langgenius Dify versions up to 1.14.2, concerning the Jinja2 Handler in the file api/core/helper/code_executor/jinja2/jinja2_transformer.py. This flaw stems from improper neutralization of special elements utilized in a template engine, specifically within the jinja2.Template function. Attackers may exploit this weakness remotely, potentially leading to unauthorized code execution. Although the vendor was notified about this vulnerability prior to its public disclosure, there was no response, raising concerns for users depending on this software.
Affected Version(s)
dify 1.14.0
dify 1.14.1
dify 1.14.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
