github.com
https://github.com/langgenius/dify/commit/378a1d7d08bd0ac5c75eaadc075a0f35211fcb8e CVE-2026-26023
MEDIUM
Client‑side DOM XSS in the web chat app of Dify when using echarts
Record summary
CVE-2026-26023 has a selected CVSS score of 5.3 (medium).
Description
Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 12, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 1.13.0 | affected |
References
3github.com
https://github.com/langgenius/dify/releases/tag/1.13.0 github.comConfirmation
https://github.com/langgenius/dify/security/advisories/GHSA-qqjx-5h5w-x5vj