github.com
https://github.com/langgenius/dify/commit/ae17537470bba417a8971fff705dd82ecb043564 CVE-2026-21866
MEDIUM
Dify - Stored XSS in chat
Record summary
CVE-2026-21866 has a selected CVSS score of 5.1 (medium).
Description
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 1.11.2 | affected |
References
3github.com
https://github.com/langgenius/dify/pull/29811 github.comConfirmation
https://github.com/langgenius/dify/security/advisories/GHSA-qpv6-75c2-75h4