Cross-Site Scripting Vulnerability in langgenius Dify Web Application
CVE-2026-85021
Key Information:
- Vendor
Langgenius
- Status
- Vendor
- CVE Published:
- 3 September 2026
Badges
What is CVE-2026-85021?
A vulnerability exists in langgenius Dify 1.13.0 due to improper handling of the redirect_url parameter in the router.replace function within the splash.tsx file of the Splash Layout component. This flaw allows attackers to execute arbitrary JavaScript in the context of the user's session, leading to potential unauthorized actions and data leakage. The attack can be conducted remotely, posing a significant risk to users. Despite the public disclosure of this exploit, the vendor did not provide a response when informed.
Affected Version(s)
dify 1.13.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
