PT-2026-84900 · Langgenius · Dify

·

CVE-2026-85021

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions langgenius dify version 1.13.0
Description Cross site scripting occurs due to the manipulation of the redirect url argument within the router.replace() function located in the web/app/(shareLayout)/components/splash.tsx file of the Splash Layout component. This issue allows for remote exploitation.
Recommendations As a temporary workaround, restrict the use of the redirect url argument in the Splash Layout component until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85021
GHSA-7QGM-PQV4-668X

Affected Products

Dify